7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24552
Simple Events Calendar Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 2 PoCs

The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue

CVE-2021-0472
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-176801033

CVE-2021-39608
Software Genérico Web
N/A
UNKNOWN
EPSS
16.9%
2021 1 PoC

Remote Code Execution (RCE) vulnerabilty exists in FlatCore-CMS 2.0.7 via the upload addon plugin, which could let a remote malicious user exeuct arbitrary php code.

CVE-2021-33504
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Couchbase Server before 7.1.0 has Incorrect Access Control.

CVE-2021-25804
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

CVE-2021-25054
WPcalc – create any online calculators Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL statement, leading to an authenticated SQL Injection vulnerability.

CVE-2021-25046
Modern Events Calendar Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Modern Events Calendar Lite WordPress plugin before 6.2.0 alloed any logged-in user, even a subscriber user, may add a category whose parameters are incorrectly escaped in the admin panel, leading to stored XSS.

CVE-2021-24916
Qubely Web Windows
N/A
UNKNOWN
EPSS
4.1%
2021 1 PoC

The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses via the qubely_send_form_data AJAX action.

CVE-2021-24993
Ultimate Product Catalog – WordPress Catalog Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF checks in some AJAX actions, which could allow any authenticated users, such as subscriber to call them and add arbitrary products, or change the plugin's settings for example

CVE-2021-26690
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
67.4%
2021 5 PoCs

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service

CVE-2021-38571
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.

CVE-2021-25424
Tizen wearable devices General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-287 1 PoC

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

CVE-2021-41426
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.

CVE-2021-28093
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.

CVE-2021-35309
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

CVE-2021-26233
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-42635
Software Genérico General
N/A
UNKNOWN
EPSS
23.5%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

CVE-2021-34805
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 2 PoCs

An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

CVE-2021-20270
python-pygments General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-835 1 PoC

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

CVE-2021-45906
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.