7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-46382
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking.

CVE-2021-20743
EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform a specific operation.

CVE-2021-33205
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library and stealing user credentials.

CVE-2021-24727
WP Block and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin StopBadBots Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 2 PoCs

The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections

CVE-2021-23934
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite through 7.10.4 allows XSS via a contact whose name contains JavaScript code.

CVE-2021-3522
GStreamer General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-125 1 PoC

GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.

CVE-2021-20660
SolarView Compact Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an arbitrary script via unspecified vectors.

CVE-2021-29395
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

CVE-2021-38714
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

CVE-2021-28963
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

CVE-2021-24823
Support Board Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-352 2 PoCs

The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files

CVE-2021-24434
Glass Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Glass WordPress plugin through 1.3.2 does not sanitise or escape its "Glass Pages" setting before outputting in a page, leading to a Stored Cross-Site Scripting issue. Furthermore, the plugin did not have CSRF check in place when saving its settings, allowing the issue to be exploited via a CSRF attack.

CVE-2021-25103
Translate WordPress with GTranslate Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Translate WordPress with GTranslate WordPress plugin before 2.9.7 does not sanitise and escape the body parameter in the url_addon/gtranslate-email.php file before outputting it back in the page, leading to a Reflected Cross-Site Scripting issue. Note: exploitation of the issue requires knowledge of the NONCE_SALT and NONCE_KEY

CVE-2021-38563
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from a /Size entry) is smaller than the maximum indirect object number, and thus there is an attempted incorrect array access (leading to a NULL pointer dereference, or out-of-bounds read or write).

CVE-2021-43186
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.

CVE-2021-4154
kernel DevOps
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-416 3 PoCs

A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.

CVE-2021-38565
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows writing to arbitrary files via submitForm.

CVE-2021-30954
watchOS General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2021-20096
OpenOversight Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

CVE-2021-3375
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.