7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-29133
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.

CVE-2021-24289
Store Locator Plus for WordPress Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-269 1 PoC

There is functionality in the Store Locator Plus for WordPress plugin through 5.5.14 that made it possible for authenticated users to update their user meta data to become an administrator on any site using the plugin.

CVE-2021-33503
Software Genérico Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

CVE-2021-29662
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVE-2021-24582
ThinkTwit Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The ThinkTwit WordPress plugin before 1.7.1 did not sanitise or escape its "Consumer key" setting before outputting it its settings page, leading to a Stored Cross-Site Scripting issue.

CVE-2021-33294
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.

CVE-2021-30180
Apache Dubbo Web
N/A
UNKNOWN
EPSS
4.4%
2021 1 PoC

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

CVE-2021-24578
SportsPress – Sports Club & League Manager Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The SportsPress WordPress plugin before 2.7.9 does not sanitise and escape its match_day parameter before outputting back in the Events backend page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-24552
Simple Events Calendar Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 2 PoCs

The Simple Events Calendar WordPress plugin through 1.4.0 does not sanitise, validate or escape the event_id POST parameter before using it in a SQL statement when deleting events, leading to an authenticated SQL injection issue

CVE-2021-37931
Software Genérico General
N/A
UNKNOWN
EPSS
37.4%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

CVE-2021-24437
Favicon by RealFaviconGenerator Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Favicon by RealFaviconGenerator WordPress plugin through 1.3.20 does not sanitise or escape one of its parameter before outputting it back in the response, leading to a Reflected Cross-Site Scripting (XSS) which is executed in the context of a logged administrator.

CVE-2021-24731
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
68.1%
2021 CWE-89 1 PoC

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.7.1.6 does not properly escape user data before using it in a SQL statement in the wp-json/pie/v1/login REST API endpoint, leading to an SQL injection.

CVE-2021-35323
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.

CVE-2021-25083
Registrations for the Events Calendar – Event Registration Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Registrations for the Events Calendar WordPress plugin before 2.7.10 does not escape the qtype parameter before outputting it back in an attribute in the settings page, leading to a Reflected Cross-Site Scripting

CVE-2021-40346
Software Genérico Web
N/A
UNKNOWN
EPSS
92.4%
2021 5 PoCs

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

CVE-2021-42565
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

CVE-2021-24424
WP Reset – Most Advanced WordPress Reset Tool Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-24884
Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
19.2%
2021 CWE-79 2 PoCs

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attack

CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-43528
Thunderbird Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.