7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-41784
Software Genérico Web
N/A
UNKNOWN
EPSS
3.2%
2021 2 PoCs

Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled.

CVE-2021-24836
Temporary Login Without Password Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-862 1 PoC

The Temporary Login Without Password WordPress plugin before 1.7.1 does not have authorisation and CSRF checks when updating its settings, which could allows any logged-in users, such as subscribers to update them

CVE-2021-24848
Mediamatic – Media Library Folders Web Database Cloud Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The mediamaticAjaxRenameCategory AJAX action of the Mediamatic WordPress plugin before 2.8.1, available to any authenticated user, does not sanitise the categoryID parameter before using it in a SQL statement, leading to an SQL injection

CVE-2021-26906
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.

CVE-2021-38291
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavutil/mathematics.c.

CVE-2021-27517
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Foxit PDF SDK For Web through 7.5.0 allows XSS. There is arbitrary JavaScript code execution in the browser if a victim uploads a malicious PDF document containing embedded JavaScript code that abuses app.alert (in the Acrobat JavaScript API).

CVE-2021-37979
Chrome General
N/A
UNKNOWN
EPSS
1.7%
2021 1 PoC

heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-33327
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.

CVE-2021-24451
Export Users With Meta Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 1 PoC

The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in a SQL statement in the export functionality, available to admins, leading to an authenticated SQL Injection.

CVE-2021-45425
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2021 3 PoCs

Reflected Cross Site Scripting (XSS) in SAFARI Montage versions 8.3 and 8.5 allows remote attackers to execute JavaScript codes.

CVE-2021-39409
Software Genérico General
N/A
UNKNOWN
EPSS
16.9%
2021 1 PoC

A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be authenticated.

CVE-2021-43288
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious JavaScript into a failed Job Report.

CVE-2021-24594
Translate WordPress – Google Language Translator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of its settings before outputting it in various pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-40578
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.7%
2021 2 PoCs

Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in PHP and PayPal Free Source Code 1.0, that allows attackers to obtain sensitive information and execute arbitrary SQL commands via IDNO parameter.

CVE-2021-45086
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used as the pdf_name value in PDF.js.

CVE-2021-37922
Software Genérico General
N/A
UNKNOWN
EPSS
26.0%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

CVE-2021-45268
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a high-privileged authenticated user who is entitled to install arbitrary add-ons

CVE-2021-45078
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

CVE-2021-33793
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.

CVE-2021-24545
WP HTML Author Bio Web Windows
N/A
UNKNOWN
EPSS
13.3%
2021 CWE-79 3 PoCs

The WP HTML Author Bio WordPress plugin through 1.2.0 does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone visit a post in the frontend made by such user. As a result, user with a role as low as author could perform Cross-Site Scripting attacks against users, which could potentially lead to privilege escalation when an admin view the related post/s.