7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-36749
Apache Druid Web ⚡ nuclei
N/A
UNKNOWN
EPSS
93.8%
2021 4 PoCs

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid directly, since Druid also provides the Local InputSource, which allows the same level of access. But it is problematic when users interact with Druid indirectly through an application that allows users to specify the HTTP InputSource, but not the Local

CVE-2021-33795
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures because the certificate name, document owner, and signature author are mishandled.

CVE-2021-28379
Software Genérico Web
N/A
UNKNOWN
EPSS
3.3%
2021 1 PoC

web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allows uploads from a different origin.

CVE-2021-24581
Blue Admin Web Windows
N/A
UNKNOWN
EPSS
1.7%
2021 CWE-352 1 PoC

The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin does not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

CVE-2021-36393
Moodle Database
N/A
UNKNOWN
EPSS
24.0%
2021 CWE-89 2 PoCs

In Moodle, an SQL injection risk was identified in the library fetching a user's recent courses.

CVE-2021-42219
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Go-Ethereum v1.10.9 was discovered to contain an issue which allows attackers to cause a denial of service (DoS) via sending an excessive amount of messages to a node. This is caused by missing memory in the component /ethash/algorithm.go.

CVE-2021-24738
Logo Carousel – Logo Slider, Logo Showcase, and Clients Logo Gallery Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Logo Carousel WordPress plugin before 3.4.2 does not validate and escape the "Logo Margin" carousel option, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-27335
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

KollectApps before 4.8.16c is affected by insecure Java deserialization, leading to Remote Code Execution via a ysoserial.payloads.CommonsCollections parameter.

CVE-2021-25041
Photo Gallery by 10Web – Mobile-Friendly Image Gallery Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Photo Gallery by 10Web WordPress plugin before 1.5.68 is vulnerable to Reflected Cross-Site Scripting (XSS) issues via the bwg_album_breadcrumb_0 and shortcode_id GET parameters passed to the bwg_frontend_data AJAX action

CVE-2021-27351
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.

CVE-2021-24716
Modern Events Calendar Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Modern Events Calendar Lite WordPress plugin before 5.22.3 does not properly sanitize or escape values set by users with access to adjust settings withing wp-admin.

CVE-2021-3118
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has multiple SQL Injection issues in the login form and the password-forgotten form (such as /req_password_user.php?email=). This allows an attacker to steal data in the database and obtain access to the application. (The database component runs as root.) NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-39408
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.php file

CVE-2021-35456
Software Genérico Database
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload

CVE-2021-25443
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-825 1 PoC

A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.

CVE-2021-26762
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2021 3 PoCs

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

CVE-2021-24905
Advanced Contact form 7 DB Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.

CVE-2021-24209
WP Super Cache Web Windows
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

CVE-2021-43287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVE-2021-30853
macOS General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6. A malicious application may bypass Gatekeeper checks.