7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24513
Form Builder | Create Responsive Contact Forms Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Form Builder | Create Responsive Contact Forms WordPress plugin before 1.9.8.4 does not sanitise or escape its Form Title, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

CVE-2021-24635
Visual Link Preview Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

The Visual Link Preview WordPress plugin before 2.2.3 does not enforce authorisation on several AJAX actions and has the CSRF nonce displayed for all authenticated users, allowing any authenticated user (such as subscriber) to call them and 1) Get and search through title and content of Draft post, 2) Get title of a password-protected post as well as 3) Upload an image from an URL

CVE-2021-40813
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames.

CVE-2021-24197
wpDataTables – Tables & Table Charts Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-284 1 PoC

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 has Improper Access Control. A low privilege authenticated user that visits the page where the table is published can tamper the parameters to access the data of another user that are present in the same table by taking over the user permissions on the table through formdata[wdt_ID] parameter. By exploiting this issue an attacker is able to access and manage the data of all users in the same table.

CVE-2021-20706
CLUSTERPRO X Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.

CVE-2021-46076
Software Genérico Web
N/A
UNKNOWN
EPSS
7.6%
2021 1 PoC

Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in multiple endpoints it leading to Code Execution.

CVE-2021-44498
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

CVE-2021-24724
Timetable and Event Schedule by MotoPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 2 PoCs

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.3.19 does not sanitise some of its parameters, which could allow low privilege users such as author to perform XSS attacks against frontend and backend users when viewing the related event/s

CVE-2021-24323
WooCommerce Web
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

When taxes are enabled, the "Additional tax classes" field was not properly sanitised or escaped before being output back in the admin dashboard, allowing high privilege users such as admin to use XSS payloads even when the unfiltered_html is disabled

CVE-2021-26571
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webgetactivexcfg function.

CVE-2021-24132
Slider by 10Web Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Slider by 10Web WordPress plugin, versions before 1.2.36, in the bulk_action, export_full and save_slider_db functionalities of the plugin were vulnerable, allowing a high privileged user (Admin), or medium one such as Contributor+ (if "Role Options" is turn on for other users) to perform a SQL Injection attacks.

CVE-2021-39273
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2021 1 PoC

In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files. This leads to arbitrary code execution with root privileges.

CVE-2021-28170
Jakarta Expression Language Implementation General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

CVE-2021-24691
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Quiz And Survey Master WordPress plugin before 7.3.2 does not escape the Quiz Url Slug setting before outputting it in some pages, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-26291
Apache Maven Web
N/A
UNKNOWN
EPSS
46.1%
2021 4 PoCs

Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to no longer follow http (non-SSL) repository references by default. More details available in the referenced urls. If you are currently using a repository manager to govern the repositories used by your builds, you are unaffected by the risks present in

CVE-2021-28293
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user.

CVE-2021-23999
Firefox ESR General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

CVE-2021-24995
HTML5 Responsive FAQ Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The HTML5 Responsive FAQ WordPress plugin through 2.8.5 does not properly sanitise and escape some of its settings, which could allow a high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2021-24507
Astra Pro Addon Web Database Windows
N/A
UNKNOWN
EPSS
44.2%
2021 CWE-89 2 PoCs

The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from the astra_pagination_infinite and astra_shop_pagination_infinite AJAX action (available to both unauthenticated and authenticated user) before using them in SQL statement, leading to an SQL Injection issues

CVE-2021-33792
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.