7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-29267
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature.

CVE-2021-1061
NVIDIA Virtual GPU Manager General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-25276
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges.

CVE-2021-43438
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field

CVE-2021-24136
Testimonials Widget Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL

CVE-2021-25306
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.

CVE-2021-24941
Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-3578
isync General
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-704 1 PoC

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.

CVE-2021-24281
Redirection for Contact Form 7 Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-863 1 PoC

In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could use the delete_action_post AJAX action to delete any post on a target site.

CVE-2021-24596
youForms for WordPress – Creating Forms for CopeCart Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24637
Fonts Plugin | Google Fonts Typography Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

CVE-2021-43442
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by parameter maniulation using PUT and DELETE and by calling the 'UserPermission' endpoint with the ID of created account and set it to 'admin' userType, successfully adding a second administrative account.

CVE-2021-38143
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name and last name. However, these fields are vulnerable to XSS payload insertion, being triggered in the admin panel when the admin tries to see the client list. This type of XSS (stored) can lead to the extraction of the PHPSESSID cookie belonging to the admin.

CVE-2021-31223
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.

CVE-2021-45839
Software Genérico Web
N/A
UNKNOWN
EPSS
54.0%
2021 1 PoC

It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.

CVE-2021-42390
clickhouse General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-369 1 PoC

Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVE-2021-41731
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field

CVE-2021-24988
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.

CVE-2021-44091
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.

CVE-2021-24181
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-89 1 PoC

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.