7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26341
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

CVE-2021-45745
Software Genérico Web
N/A
UNKNOWN
EPSS
2.7%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel.

CVE-2021-24743
Podcast Subscribe Buttons Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding posts to perform stored XSS.

CVE-2021-3612
kernel General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 2 PoCs

An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2021-24300
PickPlugins Product Slider for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.4%
2021 CWE-79 1 PoC

The slider import search feature of the PickPlugins Product Slider for WooCommerce WordPress plugin before 1.13.22 did not properly sanitised the keyword GET parameter, leading to reflected Cross-Site Scripting issue

CVE-2021-36624
Software Genérico Database
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.

CVE-2021-24747
SEO Booster Web Database Windows
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-89 1 PoC

The SEO Booster WordPress plugin before 3.8 allows for authenticated SQL injection via the "fn_my_ajaxified_dataloader_ajax" AJAX request as the $_REQUEST['order'][0]['dir'] parameter is not properly escaped leading to blind and error-based SQL injections.

CVE-2021-28001
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.

CVE-2021-43540
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95.

CVE-2021-45818
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SAFARI Montage 8.7.32 is affected by a CRLF injection vulnerability which can lead to HTTP response splitting.

CVE-2021-24221
Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
2.6%
2021 CWE-89 1 PoC

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin before 7.1.12 did not sanitise the result_id GET parameter on pages with the [qsm_result] shortcode without id attribute, concatenating it in a SQL statement and leading to an SQL injection. The lowest role allowed to use this shortcode in post or pages being author, such user could gain unauthorised access to the DBMS. If the shortcode (without the id attribute) is embed on a public page or post, then unauthenticated users could exploit the injection.

CVE-2021-23839
OpenSSL General
N/A
UNKNOWN
EPSS
0.3%
2021 5 PoCs

OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A server that supports greater than SSLv2 is supposed to reject connection attempts from a client where this special form of padding is present, because this indicates that a version rollback has occurred (i.e. both client and server support great

CVE-2021-27195
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.

CVE-2021-26400
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage.

CVE-2021-24558
Project Status Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 2 PoCs

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

CVE-2021-33214
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.

CVE-2021-40826
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary code execution in the context of the current logged-in Windows user.

CVE-2021-33057
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.

CVE-2021-42751
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.

CVE-2021-44451
Apache Superset Web ⚡ nuclei
N/A
UNKNOWN
EPSS
75.3%
2021 CWE-522 0 PoCs

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.