7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25443
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-825 1 PoC

A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.

CVE-2021-26762
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2021 3 PoCs

SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.

CVE-2021-24905
Advanced Contact form 7 DB Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF checks in the acf7_db_edit_scr_file_delete AJAX action, and does not validate the file to be deleted, allowing any authenticated user to delete arbitrary files on the web server. For example, removing the wp-config.php allows attackers to trigger WordPress setup again, gain administrator privileges and execute arbitrary code or display arbitrary content to the users.

CVE-2021-24209
WP Super Cache Web Windows
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Location option. Direct access to the wp-cache-config.php file is not prohibited, so this vulnerability can be exploited for a web shell injection.

CVE-2021-43287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVE-2021-30853
macOS General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6. A malicious application may bypass Gatekeeper checks.

CVE-2021-25095
IP2Location Country Blocker Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2location_country_blocker_save_rules AJAX action, allowing any authenticated users, such as subscriber to call it and block arbitrary country, or block all of them at once, preventing users from accessing the frontend.

CVE-2021-29006
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
20.6%
2021 2 PoCs

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

CVE-2021-24453
Include Me Web Windows
N/A
UNKNOWN
EPSS
7.2%
2021 CWE-22 1 PoC

The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to Remote Code Execution (RCE) of the system due to log poisoning and therefore potentially a full compromise of the underlying structure

CVE-2021-20083
jquery-plugin-query-object General
N/A
UNKNOWN
EPSS
7.3%
2021 1 PoC

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.

CVE-2021-44617
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

A SQL Injection vulnerability exits in the Ramo plugin for GLPI 9.4.6 via the idu parameter in plugins/ramo/ramoapirest.php/getOutdated.

CVE-2021-0330
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-170732441

CVE-2021-38751
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
8.3%
2021 0 PoCs

A HTTP Host header attack exists in ExponentCMS 2.6 and below in /exponent_constants.php. A modified HTTP header can change links on the webpage to an arbitrary value, leading to a possible attack vector for MITM.

CVE-2021-26758
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2021 2 PoCs

Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.

CVE-2021-35475
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.

CVE-2021-27358
Software Genérico DevOps Web ⚡ nuclei
N/A
UNKNOWN
EPSS
87.0%
2021 0 PoCs

The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

CVE-2021-4044
OpenSSL General
N/A
UNKNOWN
EPSS
33.3%
2021 1 PoC

Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as SSL_connect() or SSL_do_handshake()) to not indicate success and a subsequent call to SSL_get_error() to return the value SSL_ERROR_WANT_RETRY_VERIFY. This return value is only supposed to be returned by OpenSSL if the application has previously called SSL_CTX_set_cert_verify_cal

CVE-2021-24569
Cookie Notice & Compliance for GDPR / CCPA Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Cookie Notice & Compliance for GDPR / CCPA WordPress plugin before 2.1.2 does not escape the value of its Button Text setting when outputting it in an attribute in the frontend, allowing high privilege users such as admin to perform Cross-Site Scripting even when the unfiltered_html capability is disallowed.

CVE-2021-25052
Button Generator – easily Button Builder Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
42.4%
2021 CWE-352 1 PoC

The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary file with PHP extension (as well as with data:// or http:// protocols), thus leading to CSRF RCE.