7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26272
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

CVE-2021-1810
macOS General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.

CVE-2021-24750
WP Visitor Statistics (Real Time Traffic) Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
64.3%
2021 CWE-89 3 PoCs

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVE-2021-24583
Timetable and Event Schedule by MotoPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-284 1 PoC

The Timetable and Event Schedule WordPress plugin before 2.4.2 does not have proper access control when deleting a timeslot, allowing any user with the edit_posts capability (contributor+) to delete arbitrary timeslot from any events. Furthermore, no CSRF check is in place as well, allowing such attack to be performed via CSRF against a logged in with such capability

CVE-2021-46427
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.

CVE-2021-24512
Video Posts Webcam Recorder Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Video Posts Webcam Recorder WordPress plugin before 3.2.4 has an authenticated reflected cross site scripting (XSS) vulnerability in one of the administrative functions for handling deletion of videos.

CVE-2021-25801
Software Genérico General
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.

CVE-2021-25829
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.

CVE-2021-25762
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible.

CVE-2021-24206
Elementor Website Builder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

In the Elementor Website Builder WordPress plugin before 3.1.4, the image box widget (includes/widgets/image-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

CVE-2021-41878
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
15.0%
2021 3 PoCs

A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console and it is possible to insert a vulnerable malicious button.

CVE-2021-24667
Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

A stored cross-site scripting vulnerability has been discovered in : Simply Gallery Blocks with Lightbox (Version – 2.2.0 & below). The vulnerability exists in the Lightbox functionality where a user with low privileges is allowed to execute arbitrary script code within the context of the application. This vulnerability is due to insufficient validation of image parameters in meta data.

CVE-2021-25074
WebP Converter for Media – Convert WebP and AVIF & Optimize Images Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-601 1 PoC

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

CVE-2021-27971
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.

CVE-2021-26372
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

CVE-2021-31319
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-26797
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.

CVE-2021-39674
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442

CVE-2021-33515
Software Genérico General
N/A
UNKNOWN
EPSS
5.9%
2021 1 PoC

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVE-2021-24831
Tab – Accordion, FAQ Web Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-862 1 PoC

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.