7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24643
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Map Block WordPress plugin before 1.2.3 does not escape some attributes of the WP Map Block, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks

CVE-2021-42325
Software Genérico Web Database
N/A
UNKNOWN
EPSS
5.5%
2021 3 PoCs

Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.

CVE-2021-46368
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

CVE-2021-24627
G Auto-Hyperlink Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-89 2 PoCs

The G Auto-Hyperlink WordPress plugin through 1.0.1 does not sanitise or escape an 'id' GET parameter before using it in a SQL statement, to select data to be displayed in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-24373
WP Hardening – Fix Your WordPress Security Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Hardening – Fix Your WordPress Security WordPress plugin before 1.2.2 did not sanitise or escape the historyvalue GET parameter before outputting it in a Javascript block, leading to a reflected Cross-Site Scripting issue.

CVE-2021-29983
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.

CVE-2021-0430
Android General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-178725766

CVE-2021-24260
Livemesh Addons for Elementor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “Livemesh Addons for Elementor” WordPress Plugin before 6.8 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-43185
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

CVE-2021-3395
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary file. The JavaScript code will execute when someone visits the attachment.

CVE-2021-24718
Contact Form, Survey & Popup Form Plugin for WordPress – ARForms Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Contact Form, Survey & Popup Form Plugin for WordPress plugin before 1.5 does not properly sanitize some of its settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-26332
3rd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

CVE-2021-36543
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in the /op/op.UnlockDocument.php in SeedDMS v5.1.x <5.1.23 and v6.0.x <6.0.16 allows a remote attacker to unlock any document without victim's knowledge, by enticing an authenticated user to visit an attacker's web page.

CVE-2021-30149
Software Genérico Web
N/A
UNKNOWN
EPSS
17.4%
2021 2 PoCs

Composr 10.0.36 allows upload and execution of PHP files.

CVE-2021-45979
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

CVE-2021-42973
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-20157
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative command.

CVE-2021-31887
APOGEE MBC (PPC) (BACnet) General
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-170 1 PoC

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V

CVE-2021-3003
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allows man-in-the-middle attackers to spoof product updates.

CVE-2021-3487
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.