7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-31857
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.

CVE-2021-43462
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.

CVE-2021-27544
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.

CVE-2021-24587
Splash Header Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.

CVE-2021-20067
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.

CVE-2021-43334
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

BuddyBoss Platform through 1.8.0 allows XSS via the Group Name or Group Description field.

CVE-2021-24940
ووکامرس فارسی Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 1 PoC

The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue

CVE-2021-41441
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, for the router to reboot.

CVE-2021-43000
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Amzetta zPortal Windows zClient is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal Windows zClient <= v3.2.8180.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-24141
Advanced Database Cleaner Database
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high privilege users (admin+) to perform SQL attacks.

CVE-2021-30357
SSL Network Extender Client for Linux General
N/A
UNKNOWN
EPSS
30.0%
2021 CWE-209 1 PoC

SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

CVE-2021-31795
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

The PowerVR GPU kernel driver in pvrsrvkm.ko through 2021-04-24 for the Linux kernel, as used on Alcatel 1S phones, allows attackers to overwrite heap memory via PhysmemNewRamBackedPMR.

CVE-2021-24740
Tutor LMS – eLearning and online course solution Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVE-2021-3199
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2021 2 PoCs

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

CVE-2021-45998
Software Genérico General
N/A
UNKNOWN
EPSS
5.8%
2021 1 PoC

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-28060
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.

CVE-2021-37331
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL.

CVE-2021-38145
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

CVE-2021-40529
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVE-2021-40510
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.