7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24596
youForms for WordPress – Creating Forms for CopeCart Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The youForms for WordPress plugin through 1.0.5 does not sanitise escape the Button Text field of its Templates, allowing high privilege users (editors and admins) to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-24637
Fonts Plugin | Google Fonts Typography Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Google Fonts Typography WordPress plugin before 3.0.3 does not escape and sanitise some of its block settings, allowing users with as role as low as Contributor to perform Stored Cross-Site Scripting attacks via blockType (combined with content), align, color, variant and fontID argument of a Gutenberg block.

CVE-2021-43442
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by parameter maniulation using PUT and DELETE and by calling the 'UserPermission' endpoint with the ID of created account and set it to 'admin' userType, successfully adding a second administrative account.

CVE-2021-38143
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible for the customer to log in and proceed with a change of name and last name. However, these fields are vulnerable to XSS payload insertion, being triggered in the admin panel when the admin tries to see the client list. This type of XSS (stored) can lead to the extraction of the PHPSESSID cookie belonging to the admin.

CVE-2021-31223
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

SES Evolution before 2.1.0 allows reading some parts of a security policy by leveraging access to a computer having the administration console installed.

CVE-2021-45839
Software Genérico Web
N/A
UNKNOWN
EPSS
54.0%
2021 1 PoC

It is possible to obtain the first administrator's hash set up on the system in Terramaster F4-210, F2-210 TOS 4.2.X (4.2.15-2107141517) as well as other information such as MAC address, internal IP address etc. by performing a request to the /module/api.php?mobile/webNasIPS endpoint.

CVE-2021-42390
clickhouse General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-369 1 PoC

Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVE-2021-41731
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field

CVE-2021-24988
WP RSS Aggregator – News Feeds, Autoblogging, Youtube Video Feeds and More Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.

CVE-2021-44091
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.

CVE-2021-24181
Tutor LMS – eLearning and online course solution Web Database Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-89 1 PoC

The tutor_mark_answer_as_correct AJAX action from the Tutor LMS – eLearning and online course solution WordPress plugin before 1.7.7 was vulnerable to blind and time based SQL injections that could be exploited by students.

CVE-2021-28249
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the library will be executed as the root user. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-21156
Chrome General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.

CVE-2021-35336
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.8%
2021 1 PoC

Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.

CVE-2021-24540
Wonder Video Embed Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Wonder Video Embed WordPress plugin before 1.8 does not escape parameters of its wonderplugin_video shortcode, which could allow users with a role as low as Contributor to perform Stored XSS attacks.

CVE-2021-20187
moodle Web
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-94 1 PoC

It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.

CVE-2021-37841
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the server running the Windows containers, it can lead to a full container compromise in both process isolation and Hyper-V isolation modes. This security issue leads an attacker with low privilege to read, write and possibly even execute code inside the containers.

CVE-2021-34430
Eclipse TinyDTLS General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-338 1 PoC

Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

CVE-2021-3561
fig2dev General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-119 2 PoCs

An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide a crafted malicious input causing the application to either crash or in some cases cause memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

CVE-2021-28095
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash collisions can occur, due to use of CRC32.