7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-23839
OpenSSL General
N/A
UNKNOWN
EPSS
0.3%
2021 5 PoCs

OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A server that supports greater than SSLv2 is supposed to reject connection attempts from a client where this special form of padding is present, because this indicates that a version rollback has occurred (i.e. both client and server support great

CVE-2021-27195
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic.

CVE-2021-26400
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage.

CVE-2021-24558
Project Status Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 2 PoCs

The pspin_duplicate_post_save_as_new_post function of the Project Status WordPress plugin through 1.6 does not sanitise, validate or escape the post GET parameter passed to it before outputting it in an error message when the related post does not exist, leading to a reflected XSS issue

CVE-2021-33214
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could lead to sensitive information disclosure, modification of configuration files, or disruption of normal system operation.

CVE-2021-40826
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit this issue to cause a crash (DoS) of the clementine.exe process or achieve arbitrary code execution in the context of the current logged-in Windows user.

CVE-2021-33057
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.

CVE-2021-42751
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to inject arbitrary JavaScript within the description of a rule node.

CVE-2021-44451
Apache Superset Web ⚡ nuclei
N/A
UNKNOWN
EPSS
75.3%
2021 CWE-522 0 PoCs

Apache Superset up to and including 1.3.2 allowed for registered database connections password leak for authenticated users. This information could be accessed in a non-trivial way. Users should upgrade to Apache Superset 1.4.0 or higher.

CVE-2021-22096
Spring Framework Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-117 1 PoC

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVE-2021-41038
@theia/plugin-ext General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-940 1 PoC

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

CVE-2021-24697
Simple Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVE-2021-31604
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.

CVE-2021-24669
MAZ Loader – Preloader Builder for WordPress Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The MAZ Loader – Preloader Builder for WordPress plugin before 1.3.3 does not validate or escape the loader_id parameter of the mzldr shortcode, which allows users with a role as low as Contributor to perform SQL injection.

CVE-2021-24789
Flat Preloader Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Flat Preloader WordPress plugin before 1.5.5 does not escape some of its settings when outputting them in attribute in the frontend, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed

CVE-2021-24722
Restaurant Menu by MotoPress Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Restaurant Menu by MotoPress WordPress plugin before 2.4.2 does not properly sanitize or escape inputs when creating new menu items, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-25062
Orders Tracking for WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-38149
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.

CVE-2021-40088
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in PrimeKey EJBCA before 7.6.0. CMP RA Mode can be configured to use a known client certificate to authenticate enrolling clients. The same RA client certificate is used for revocation requests as well. While enrollment enforces multi tenancy constraints (by verifying that the client certificate has access to the CA and Profiles being enrolled against), this check was not performed when authenticating revocation operations, allowing a known tenant to revoke a certificate belonging to another tenant.

CVE-2021-41442
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.