7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-38568
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.

CVE-2021-42071
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 2 PoCs

In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharacters in the cgi-bin/slogin/login.py User-Agent HTTP header.

CVE-2021-33839
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.

CVE-2021-3378
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.

CVE-2021-42913
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.5%
2021 4 PoCs

The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.

CVE-2021-24814
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
17.2%
2021 1 PoC

The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.26, available to both unauthenticated and authenticated users, responds with JSON data without an "application/json" content-type. Since an HTML payload isn't properly escaped, it may be interpreted by a web browser led to this endpoint. Javascript code may be executed on a victim's browser. If the victim is an administrator with a valid session cookie, full control of the WordPress instance may be taken (AJAX calls and iframe manipulation are possible because the vulnerable endpoint is on the same domain

CVE-2021-24561
WP SMS Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP SMS WordPress plugin before 5.4.13 does not sanitise the "wp_group_name" parameter before outputting it back in the "Groups" page, leading to an Authenticated Stored Cross-Site Scripting issue

CVE-2021-3010
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

There are multiple persistent cross-site scripting (XSS) vulnerabilities in the web interface of OpenText Content Server Version 20.3. The application allows a remote attacker to introduce arbitrary JavaScript by crafting malicious form values that are later not sanitized.

CVE-2021-31797
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 3 PoCs

The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.

CVE-2021-24666
Podlove Podcast Publisher Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
86.0%
2021 CWE-89 1 PoC

The Podlove Podcast Publisher WordPress plugin before 3.5.6 contains a 'Social & Donations' module (not activated by default), which adds the rest route '/services/contributor/(?P<id>[\d]+), takes an 'id' and 'category' parameters as arguments. Both parameters can be used for the SQLi.

CVE-2021-43162
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.1915 / EW_3.0(1)B11P55 via the runPackDiagnose function in /cgi-bin/luci/api/diagnose.

CVE-2021-44906
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 2 PoCs

Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).

CVE-2021-42664
Software Genérico Web
N/A
UNKNOWN
EPSS
1.9%
2021 5 PoCs

A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Quiz title and (2) quiz description parameters to add_quiz.php. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf, which can lead to cookie stealing and more.

CVE-2021-26392
AMD Radeon RX 5000 Series & PRO W5000 Series General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

CVE-2021-22060
Spring Framework Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVE-2021-44565
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Cross Site Scripting (XSS) vulnerability exists in RosarioSIS before 7.6.1 via the xss_clean function in classes/Security.php, which allows remote malicious users to inject arbitrary JavaScript or HTML. An example of affected components are all Markdown input fields.

CVE-2021-32158
Software Genérico Web
N/A
UNKNOWN
EPSS
8.1%
2021 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 via the Upload and Download feature.

CVE-2021-20107
SLOAN General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.

CVE-2021-20121
Telus Wi-Fi Hub (PRV65B444A-S-TS) General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is vulnerable to an authenticated arbitrary file read. An authenticated user with physical access to the device can read arbitrary files from the device by preparing and connecting a specially prepared USB drive to the device, and making a series of crafted requests to the device's web interface.

CVE-2021-24395
Embed Youtube Video Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The editid GET parameter of the Embed Youtube Video WordPress plugin through 1.0 is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection.