7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-40346
Software Genérico Web
N/A
UNKNOWN
EPSS
92.4%
2021 5 PoCs

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

CVE-2021-42565
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

myfactory.FMS before 7.1-912 allows XSS via the UID parameter.

CVE-2021-24424
WP Reset – Most Advanced WordPress Reset Tool Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The WP Reset – Most Advanced WordPress Reset Tool WordPress plugin before 1.90 did not sanitise or escape its extra_data parameter when creating a snapshot via the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-35309
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

CVE-2021-24829
Visitor Traffic Real Time Statistics Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue

CVE-2021-20270
python-pygments General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-835 1 PoC

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

CVE-2021-24884
Formidable Form Builder – Contact Form, Survey & Quiz Forms Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
19.2%
2021 CWE-79 2 PoCs

The Formidable Form Builder WordPress plugin before 4.09.05 allows to inject certain HTML Tags like <audio>,<video>,<img>,<a> and<button>.This could allow an unauthenticated, remote attacker to exploit a HTML-injection byinjecting a malicous link. The HTML-injection may trick authenticated users to follow the link. If the Link gets clicked, Javascript code can be executed. The vulnerability is due to insufficient sanitization of the "data-frmverify" tag for links in the web-based entry inspection page of affected systems. A successful exploitation incomibantion with CSRF could allow the attack

CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-43528
Thunderbird Web
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level privileges, but could be used as a stepping stone to further an attack with other vulnerabilities. This vulnerability affects Thunderbird < 91.4.0.

CVE-2021-22014
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

The vCenter Server contains an authenticated code execution vulnerability in VAMI (Virtual Appliance Management Infrastructure). An authenticated VAMI user with network access to port 5480 on vCenter Server may exploit this issue to execute code on the underlying operating system that hosts vCenter Server.

CVE-2021-25427
Samsung Mobile Devices Database
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-89 1 PoC

SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information

CVE-2021-45980
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.

CVE-2021-26362
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.

CVE-2021-24670
CoolClock – a Javascript Analog Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

CVE-2021-44033
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.

CVE-2021-4057
Chrome Web
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-41738
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2021 2 PoCs

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

CVE-2021-40159
Inventor General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.

CVE-2021-24462
Photo Gallery by Ays – Responsive Image Gallery Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-25085
WOOF – Products Filter for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.2%
2021 CWE-79 1 PoC

The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting