7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24130
WP Google Map Plugin Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).

CVE-2021-38093
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

CVE-2021-43137
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via the name field in my-profile.php. Chaining to this both vulnerabilities leads to account takeover.

CVE-2021-31616
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2021 1 PoC

Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow via crafted messages. The overflow in ethereum_extractThorchainSwapData() in ethereum.c can circumvent stack protections and lead to code execution. The vulnerable interface is reachable remotely over WebUSB.

CVE-2021-31680
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.

CVE-2021-25330
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-37819
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.

CVE-2021-24943
Registrations for the Events Calendar – Event Registration Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
55.5%
2021 CWE-89 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.6 does not sanitise and escape the event_id in the rtec_send_unregister_link AJAX action (available to both unauthenticated and authenticated users) before using it in a SQL statement, leading to an unauthenticated SQL injection.

CVE-2021-26903
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

LMA ISIDA Retriever 5.2 is vulnerable to XSS via query['text'].

CVE-2021-26408
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.

CVE-2021-3315
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.

CVE-2021-20718
mod_auth_openidc General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

CVE-2021-24653
Cookie Bar Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Cookie Bar WordPress plugin before 1.8.9 doesn't properly sanitise the Cookie Bar Message setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-28429
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.

CVE-2021-25893
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

CVE-2021-30956
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A lock screen issue allowed access to contacts on a locked device. This issue was addressed with improved state management. This issue is fixed in iOS 15.2 and iPadOS 15.2. An attacker with physical access to a device may be able to see private contact information.

CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.3%
2021 CWE-89 3 PoCs

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVE-2021-3151
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attackers to inject arbitrary web script or HTML via C__MONITORING__CONFIG__TITLE, SM2__C__MONITORING__CONFIG__TITLE, C__MONITORING__CONFIG__PATH, SM2__C__MONITORING__CONFIG__PATH, C__MONITORING__CONFIG__ADDRESS, or SM2__C__MONITORING__CONFIG__ADDRESS.

CVE-2021-46363
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

CVE-2021-23932
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.