7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-40492
Software Genérico Web
N/A
UNKNOWN
EPSS
10.0%
2021 1 PoC

A reflected XSS vulnerability exists in multiple pages in version 22 of the Gibbon application that allows for arbitrary execution of JavaScript (gibbonCourseClassID, gibbonPersonID, subpage, currentDate, or allStudents to index.php).

CVE-2021-24692
Simple Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.7%
2021 CWE-22 1 PoC

The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.

CVE-2021-39459
Software Genérico Web
N/A
UNKNOWN
EPSS
10.1%
2021 1 PoC

Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.

CVE-2021-36707
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.

CVE-2021-33617
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

CVE-2021-42389
clickhouse General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-369 1 PoC

Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVE-2021-36389
Software Genérico Web
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Reference vulnerability exploitable by sending a specially crafted HTTP GET request to the page "MIImage.i4".

CVE-2021-24446
Remove Footer Credit Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Remove Footer Credit WordPress plugin before 1.0.6 does not have CSRF check in place when saving its settings, which could allow attacker to make logged in admins change them and lead to Stored XSS issue as well due to the lack of sanitisation

CVE-2021-24717
AutomatorWP Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The AutomatorWP WordPress plugin before 1.7.6 does not perform capability checks which allows users with Subscriber roles to enumerate automations, disclose title of private posts or user emails, call functions, or perform privilege escalation via Ajax actions.

CVE-2021-44493
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a call to $Extract to force an signed integer holding the size of a buffer to take on a large negative number, which is then used as the length of a memcpy call that occurs on the stack, causing a buffer overflow.

CVE-2021-43196
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.

CVE-2021-1060
NVIDIA Virtual GPU Software General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-43039
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

CVE-2021-43617
Software Genérico Web
N/A
UNKNOWN
EPSS
50.1%
2021 3 PoCs

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

CVE-2021-40662
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

A Cross-Site Request Forgery (CSRF) in Chamilo LMS 1.11.14 allows attackers to execute arbitrary commands on victim hosts via user interaction with a crafted URL.

CVE-2021-20126
Draytek VigorConnect Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.

CVE-2021-26311
SEV/SEV-ES General
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

CVE-2021-37808
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.2%
2021 4 PoCs

SQL Injection vulnerabilities exist in https://phpgurukul.com News Portal Project 3.1 via the (1) category, (2) subcategory, (3) sucatdescription, and (4) username parameters, the server response is about (N) seconds delay respectively which mean it is vulnerable to MySQL Blind (Time Based). An attacker can use sqlmap to further the exploitation for extracting sensitive information from the database.

CVE-2021-29023
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

CVE-2021-40579
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

https://www.sourcecodester.com/ Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 is affected by: Incorrect Access Control. The impact is: gain privileges (remote).