7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25081
Maps Plugin using Google Maps for WordPress – WP Google Map Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack

CVE-2021-24703
Download Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-732 1 PoC

The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.

CVE-2021-32923
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

CVE-2021-39375
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValue parameter.

CVE-2021-24704
Orange Form Web Database Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-89 1 PoC

In the Orange Form WordPress plugin through 1.0, the process_bulk_action() function in "admin/orange-form-email.php" performs an unprepared SQL query with an unsanitized parameter ($id). Only admin can access the page that invokes the function, but because of lack of CSRF protection, it is actually exploitable and could allow attackers to make a logged in admin delete arbitrary posts for example

CVE-2021-30150
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Composr 10.0.36 allows XSS in an XML script.

CVE-2021-44217
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitrary web script or HTML via the POST JSON data of the /CodeCheckerService API.

CVE-2021-31888
APOGEE MBC (PPC) (BACnet) General
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-170 1 PoC

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V

CVE-2021-43038
Software Genérico Database
N/A
UNKNOWN
EPSS
2.3%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by injecting into PostgreSQL trigger functions. This allowed privilege escalation from the wguest user to the postgres user.

CVE-2021-33220
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. Hard-coded API Keys exist.

CVE-2021-28665
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

CVE-2021-41445
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.

CVE-2021-26710
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
21.1%
2021 0 PoCs

A cross-site scripting (XSS) issue in the login panel in Redwood Report2Web 4.3.4.5 and 4.5.3 allows remote attackers to inject JavaScript via the signIn.do urll parameter.

CVE-2021-43334
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.

CVE-2021-46416
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

CVE-2021-24308
LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 2 PoCs

The 'State' field of the Edit profile page of the LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.1 is not properly sanitised when output in the About section of the profile page, leading to a stored Cross-Site Scripting issue. This could allow low privilege users (such as students) to elevate their privilege via an XSS attack when an admin will view their profile.

CVE-2021-24145
Modern Events Calendar Lite Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 CWE-434 4 PoCs

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

CVE-2021-22901
https://github.com/curl/curl Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-416 3 PoCs

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplex

CVE-2021-24313
WP Prayer Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 2 PoCs

The WP Prayer WordPress plugin before 1.6.2 provides the functionality to store requested prayers/praises and list them on a WordPress website. These stored prayer/praise requests can be listed by using the WP Prayer engine. An authenticated WordPress user with any role can fill in the form to request a prayer. The form to request prayers or praises have several fields. The 'prayer request' and 'praise request' fields do not use proper input validation and can be used to store XSS payloads.

CVE-2021-24467
Leaflet Map Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Leaflet Map WordPress plugin before 3.0.0 does not verify the CSRF nonce when saving its settings, which allows attackers to make a logged in admin update the settings via a Cross-Site Request Forgery attack. This could lead to Cross-Site Scripting issues by either changing the URL of the JavaScript library being used, or using malicious attributions which will be executed in all page with an embed map from the plugin