7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-28423
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.7%
2021 3 PoCs

Multiple SQL Injection vulnerabilities in Teachers Record Management System 1.0 thru 2.1 allow remote authenticated users to execute arbitrary SQL commands via the 'editid' GET parameter in edit-subjects-detail.php, edit-teacher-detail.php, or the 'searchdata' POST parameter in search.php.

CVE-2021-3346
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template.

CVE-2021-29060
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.

CVE-2021-24514
Visual Form Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Visual Form Builder WordPress plugin before 3.0.4 does not sanitise or escape its Form Name, allowing high privilege users such as admin to set Cross-Site Scripting payload in them, even when the unfiltered_html capability is disallowed

CVE-2021-31319
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-33515
Software Genérico General
N/A
UNKNOWN
EPSS
5.9%
2021 1 PoC

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVE-2021-25680
Software Genérico Web
N/A
UNKNOWN
EPSS
1.7%
2021 2 PoCs

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched

CVE-2021-24831
Tab – Accordion, FAQ Web Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-862 1 PoC

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

CVE-2021-24261
HT Mega – Absolute Addons for Elementor Page Builder Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The “HT Mega – Absolute Addons for Elementor Page Builder” WordPress Plugin before 1.5.7 has several widgets that are vulnerable to stored Cross-Site Scripting (XSS) by lower-privileged users such as contributors, all via a similar method.

CVE-2021-24550
Broken Link Manager Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise, validate or escape the url GET parameter before using it in a SQL statement when retrieving an URL to edit, leading to an authenticated SQL injection issue

CVE-2021-24900
Ninja Tables – Best WP DataTables Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 2 PoCs

The Ninja Tables WordPress plugin before 4.1.8 does not sanitise and escape some of its table fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-25115
WP Photo Album Plus Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

CVE-2021-24276
Contact Form by Supsystic Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2021 CWE-79 2 PoCs

The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-30862
iTunes U Web
N/A
UNKNOWN
EPSS
2.2%
2021 2 PoCs

A validation issue was addressed with improved input sanitization. This issue is fixed in iTunes U 3.8.3. Processing a maliciously crafted URL may lead to arbitrary javascript code execution.

CVE-2021-32919
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).

CVE-2021-25063
Skins for Contact Form 7 Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-79 1 PoC

The Skins for Contact Form 7 WordPress plugin before 2.5.1 does not sanitise and escape the tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-24454
YOP Poll Web Windows
N/A
UNKNOWN
EPSS
1.7%
2021 CWE-79 1 PoC

In the YOP Poll WordPress plugin before 6.2.8, when a pool is created with the options "Allow other answers", "Display other answers in the result list" and "Show results", it can lead to Stored Cross-Site Scripting issues as the 'Other' answer is not sanitised before being output in the page. The execution of the XSS payload depends on the 'Show results' option selected, which could be before or after sending the vote for example.

CVE-2021-28855
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (src/deark-dbuf.c).

CVE-2021-30146
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."

CVE-2021-27198
Software Genérico Windows
N/A
UNKNOWN
EPSS
14.2%
2021 4 PoCs

An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur via Arbitrary File Upload in the web service when using a myspeed/sf?filename= URI. This application is written in Java and is thus cross-platform. The Windows installation runs as SYSTEM, which means that exploitation gives one Administrator privileges on the target system.