7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25099
GiveWP – Donation Plugin and Fundraising Platform Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.4%
2021 CWE-79 1 PoC

The GiveWP WordPress plugin before 2.17.3 does not sanitise and escape the form_id parameter before outputting it back in the response of an unauthenticated request via the give_checkout_login AJAX action, leading to a Reflected Cross-Site Scripting

CVE-2021-46073
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List Section in login panel.

CVE-2021-25030
Events Made Easy Web Database Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-89 1 PoC

The Events Made Easy WordPress plugin before 2.2.36 does not sanitise and escape the search_text parameter before using it in a SQL statement via the eme_searchmail AJAX action, available to any authenticated users. As a result, users with a role as low as subscriber can call it and perform SQL injection attacks

CVE-2021-40087
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in PrimeKey EJBCA before 7.6.0. When audit logging changes to the alias configurations of various protocols that use an enrollment secret, any modifications to the secret were logged in cleartext in the audit log (that can only be viewed by an administrator). This affects use of any of the following protocols: SCEP, CMP, or EST.

CVE-2021-41918
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects every endpoint on the application because it is related on how each URL is echoed back on every response page.

CVE-2021-24173
VM Backups Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The VM Backups WordPress plugin through 1.0 does not have CSRF checks, allowing attackers to make a logged in user unwanted actions, such as update the plugin's options, leading to a Stored Cross-Site Scripting issue.

CVE-2021-24236
Imagements Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
74.1%
2021 CWE-434 1 PoC

The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Content-Type in the request to forbid dangerous files. This allows unauthenticated attackers to upload arbitrary files by using a valid image Content-Type along with a PHP filename and code, leading to RCE.

CVE-2021-41550
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

CVE-2021-24889
Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Ninja Forms Contact Form WordPress plugin before 3.6.4 does not escape keys of the fields POST parameter, which could allow high privilege users to perform SQL injections attacks

CVE-2021-24498
Calendar Event Multi View Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.5%
2021 CWE-79 1 PoC

The Calendar Event Multi View WordPress plugin before 1.4.01 does not sanitise or escape the 'start' and 'end' GET parameters before outputting them in the page (via php/edit.php), leading to a reflected Cross-Site Scripting issue.

CVE-2021-24463
Image Slider by Ays- Responsive Slider and Carousel Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_sliders() function in the Image Slider by Ays- Responsive Slider and Carousel WordPress plugin before 2.5.0 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-31229
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.

CVE-2021-31898
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains WebStorm before 2021.1, HTTP requests were used instead of HTTPS.

CVE-2021-41653
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.9%
2021 3 PoCs

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

CVE-2021-44492
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, attackers can cause a type to be incorrectly initialized in the function f_incr in sr_port/f_incr.c and cause a crash due to a NULL pointer dereference.

CVE-2021-38572
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows writing to arbitrary files because the extractPages pathname is not validated.

CVE-2021-43397
Software Genérico General
N/A
UNKNOWN
EPSS
18.3%
2021 1 PoC

LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.

CVE-2021-24547
KN Fix Your Title Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The KN Fix Your Title WordPress plugin through 1.0.1 was vulnerable to Authenticated Stored XSS in the separator field.

CVE-2021-25425
Samsung Health General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-703 1 PoC

Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.

CVE-2021-45803
Software Genérico Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when viewing reservation.