7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3199
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2021 2 PoCs

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

CVE-2021-45998
Software Genérico General
N/A
UNKNOWN
EPSS
5.8%
2021 1 PoC

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-28060
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET requests to arbitrary URLs via the url parameter to group/api/upload.php.

CVE-2021-37331
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL.

CVE-2021-38145
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

An issue was discovered in Form Tools through 3.0.20. SQL Injection can occur via the export_group_id field when a low-privileged user (client) tries to export a form with data, e.g., manipulation of modules/export_manager/export.php?export_group_id=1&export_group_1_results=all&export_type_id=1.

CVE-2021-40529
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVE-2021-40510
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

CVE-2021-45744
Software Genérico Web
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel.

CVE-2021-24723
WP Reactions Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Reactions Lite WordPress plugin before 1.3.6 does not properly sanitize inputs within wp-admin pages, allowing users with sufficient access to inject XSS payloads within /wp-admin/ pages.

CVE-2021-24369
WordPress Payments Plugin | GetPaid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

In the GetPaid WordPress plugin before 2.3.4, users with the contributor role and above can create a new Payment Form, however the Label and Help Text input fields were not getting sanitized properly. So it was possible to inject malicious content such as img tags, leading to a Stored Cross-Site Scripting issue which is triggered when the form will be edited, for example when an admin reviews it and could lead to privilege escalation.

CVE-2021-20169
Netgear RAX43 Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be transmitted in cleartext.

CVE-2021-3293
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
62.1%
2021 0 PoCs

emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webroot/file.

CVE-2021-24421
WP JobSearch Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP JobSearch WordPress plugin before 1.7.4 did not sanitise or escape multiple of its parameters from the my-resume page before outputting them in the page, allowing low privilege users to use JavaScript payloads in them and leading to a Stored Cross-Site Scripting issue

CVE-2021-35458
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.5%
2021 3 PoCs

Online Pet Shop We App 1.0 is vulnerable to Union SQL Injection in products.php (aka p=products) via the c or s parameter.

CVE-2021-44664
Software Genérico Web
N/A
UNKNOWN
EPSS
15.0%
2021 2 PoCs

An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in website_code/php/import/fileupload.php by uploading a maliciously crafted PHP file though the project interface disguised as a language file to bypasses the upload filters. Attackers can manipulate the files destination by abusing path traversal in the 'mediapath' variable.

CVE-2021-32920
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2021 2 PoCs

Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.

CVE-2021-24272
fitness calculators Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 2 PoCs

The fitness calculators WordPress plugin before 1.9.6 add calculators for Water intake, BMI calculator, protein Intake, and Body Fat and was lacking CSRF check, allowing attackers to make logged in users perform unwanted actions, such as change the calculator headers. Due to the lack of sanitisation, this could also lead to a Stored Cross-Site Scripting issue

CVE-2021-31613
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle the reception of a truncated LMP packet during the LMP auto rate procedure, allowing attackers in radio range to immediately crash (and restart) a device via a crafted LMP packet.

CVE-2021-3137
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

CVE-2021-31800
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
39.8%
2021 2 PoCs

Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.