7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-31552
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create an account (and not the user account itself). Such rules could also be used by a nefarious, unprivileged user to catalog and enumerate any number of IP addresses related to these account creations.

CVE-2021-28376
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

CVE-2021-32563
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 2 PoCs

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVE-2021-29953
Firefox Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A malicious webpage could have forced a Firefox for Android user into executing attacker-controlled JavaScript in the context of another domain, resulting in a Universal Cross-Site Scripting vulnerability. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected. Further details are being temporarily withheld to allow users an opportunity to update.*. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3.

CVE-2021-40247
Software Genérico Database
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.

CVE-2021-30949
watchOS General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.

CVE-2021-41504
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-20654
Wekan Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 2 PoCs

Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scripting. This is named 'Fieldbleed' in the vendor's site.

CVE-2021-44508
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). A lack of NULL checks in calls to ious_open in sr_unix/ious_open.c allows attackers to crash the application by dereferencing a NULL pointer.

CVE-2021-44224
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
11.0%
2021 CWE-476 2 PoCs

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVE-2021-34798
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
10.3%
2021 CWE-476 3 PoCs

Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVE-2021-25947
nestie General
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-24707
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Learning Courses WordPress plugin before 5.0 does not sanitise and escape the Email PDT identity token settings, which could allow high privilege users to perform cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24194
Login Protection – Limit Failed Login Attempts Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-24191
WP Maintenance Mode & Site Under Construction Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-26574
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.

CVE-2021-24615
微信打赏(Wechat Reward) Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.

CVE-2021-21990
Vmware Workspace One UEM console Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 2003 prior to 20.3.0.23, 2001 prior to 20.1.0.32, 1912 prior to 19.12.0.24) contain a cross-site scripting vulnerability. VMware Workspace ONE UEM console does not validate incoming requests during device enrollment after leading to rendering of unsanitized input on the user device in response.

CVE-2021-24403
WordPress Page Contact Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The Orders functionality in the WordPress Page Contact plugin through 1.0 has an order_id parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors

CVE-2021-24643
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks