7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-41674
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An SQL Injection vulnerability exists in Sourcecodester E-Negosyo System 1.0 via the user_email parameter in /admin/login.php.

CVE-2021-37379
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability in Teradek Sphere all firmware versions allows remote attackers to run arbitrary code via the Friendly Name field in System Information Settings. NOTE: Vedor states the product has reached End of Life and will not be receiving any firmware updates to address this issue.

CVE-2021-20707
CLUSTERPRO X Windows
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to read files upload via network..

CVE-2021-27315
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
31.5%
2021 1 PoC

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.

CVE-2021-43542
Thunderbird Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-27706
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.1%
2021 1 PoC

Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the parameter "IPMacBindIndex" to strcpy without limit.

CVE-2021-24927
My Calendar Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The My Calendar WordPress plugin before 3.2.18 does not sanitise and escape the callback parameter of the mc_post_lookup AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected Cross-Site Scripting issue

CVE-2021-20122
Telus Wi-Fi Hub (PRV65B444A-S-TS) Networking
N/A
UNKNOWN
EPSS
8.5%
2021 1 PoC

The Telus Wi-Fi Hub (PRV65B444A-S-TS) with firmware version 3.00.20 is affected by an authenticated command injection vulnerability in multiple parameters passed to tr69_cmd.cgi. A remote attacker connected to the router's LAN and authenticated with a super user account, or using a bypass authentication vulnerability like CVE-2021-20090 could leverage this issue to run commands or gain a shell as root on the target device.

CVE-2021-24733
WP Post Page Clone Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.

CVE-2021-24140
Ajax Load More Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvalidated input in the Ajax Load More WordPress plugin, versions before 5.3.2, lead to SQL Injection in POST /wp-admin/admin-ajax.php with param repeater=' or sleep(5)#&type=test.

CVE-2021-38569
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.

CVE-2021-23926
Apache XMLBeans Web
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

CVE-2021-37160
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

A firmware validation issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. There is no firmware validation (e.g., cryptographic signature validation) during a File Upload for a firmware update.

CVE-2021-25106
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages WordPress plugin before 2.7.1 does not check for authorisation and has a flawed CSRF logic when saving its settings, allowing any authenticated users, such as subscriber, to update them. Furthermore, due to the lack of sanitisation and escaping, it could lead to Stored Cross-Site Scripting

CVE-2021-45227
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file upload functionality is vulnerable to a persistent Cross-Site Scripting (XSS) attack.

CVE-2021-25778
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.

CVE-2021-40827
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move, affecting the MP3 file parsing functionality at memcpy+0x265. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary code execution in the context of the current logged-in Windows user.

CVE-2021-45901
Software Genérico General
N/A
UNKNOWN
EPSS
19.6%
2021 4 PoCs

The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.

CVE-2021-26272
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

CVE-2021-1810
macOS General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.