7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24288
Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2021 CWE-601 1 PoC

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

CVE-2021-24135
WP Customer Reviews Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the WP Customer Reviews WordPress plugin, versions before 3.4.3, lead to multiple Stored Cross-Site Scripting vulnerabilities allowing remote attackers to inject arbitrary JavaScript code or HTML.

CVE-2021-38509
Firefox Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVE-2021-43734
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
77.4%
2021 0 PoCs

kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.

CVE-2021-25944
deep-defaults General
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-38566
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows stack consumption during recursive processing of embedded XML nodes.

CVE-2021-24442
Poll, Survey, Questionnaire and Voting system Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.5%
2021 CWE-89 1 PoC

The Poll, Survey, Questionnaire and Voting system WordPress plugin before 1.5.3 did not sanitise, escape or validate the date_answers[] POST parameter before using it in a SQL statement when sending a Poll result, allowing unauthenticated users to perform SQL Injection attacks

CVE-2021-38147
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
78.7%
2021 1 PoC

Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as reports containing sensitive information, because authentication is not required for API access to processexecution/DownloadExcelFile/Domain_Credential_Report_Excel, processexecution/DownloadExcelFile/User_Report_Excel, processexecution/DownloadExcelFile/Process_Report_Excel, processexecution/DownloadExcelFile/Infrastructure_Report_Excel, or processexecution/DownloadExcelFile/Resolver_Report_Excel.

CVE-2021-24756
WP System Log Web Windows
N/A
UNKNOWN
EPSS
14.8%
2021 CWE-79 1 PoC

The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.

CVE-2021-36668
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App.

CVE-2021-34553
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

CVE-2021-27308
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter.

CVE-2021-24344
Easy Preloader Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+) Stored Cross-Site scripting issues

CVE-2021-24513
Form Builder | Create Responsive Contact Forms Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

CVE-2021-24635
Visual Link Preview Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

CVE-2021-40813
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames.

CVE-2021-24197
wpDataTables – Tables & Table Charts Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-284 1 PoC

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

CVE-2021-20706
CLUSTERPRO X Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.

CVE-2021-46076
Software Genérico Web
N/A
UNKNOWN
EPSS
7.6%
2021 1 PoC

Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

CVE-2021-44498
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.