7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24138
AdRotate Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

Unvalidated input in the AdRotate WordPress plugin, versions before 5.8.4, leads to Authenticated SQL injection via param "id". This requires an admin privileged user.

CVE-2021-25755
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the encrypted traffic.

CVE-2021-43193
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

CVE-2021-38586
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In cPanel before 98.0.1, /scripts/cpan_config performs unsafe operations on files (SEC-589).

CVE-2021-29660
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 allows attackers to reset the administrative password by inducing the Administrator user to browse a URL controlled by an attacker.

CVE-2021-24919
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection

CVE-2021-38705
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.

CVE-2021-25068
Sync WooCommerce Product feed to Google Shopping Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 1 PoC

The Sync WooCommerce Product feed to Google Shopping WordPress plugin through 1.2.4 uses the 'feed_id' POST parameter which is not properly sanitized for use in a SQL statement, leading to a SQL injection vulnerability in the admin dashboard

CVE-2021-37402
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via binary data that is mishandled when the legacy dataretrieval endpoint has been enabled.

CVE-2021-30129
Apache Mina SSHD Web Networking
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0

CVE-2021-0394
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In android_os_Parcel_readString8 of android_os_Parcel.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-172655291

CVE-2021-28417
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php and the "search_name" parameter.

CVE-2021-24522
User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The User Registration, User Profile, Login & Membership – ProfilePress (Formerly WP User Avatar) WordPress plugin before 3.1.11's widget for tabbed login/register was not properly escaped and could be used in an XSS attack which could lead to wp-admin access. Further, the plugin in several places assigned $_POST as $_GET which meant that in some cases this could be replicated with just $_GET parameters and no need for $_POST values.

CVE-2021-27885
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.

CVE-2021-25922
openemr Web
N/A
UNKNOWN
EPSS
1.7%
2021 1 PoC

In OpenEMR, versions 4.2.0 to 6.0.0 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly. An attacker could trick a user to click on a malicious url and execute malicious code.

CVE-2021-24668
MAZ Loader – Preloader Builder for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The MAZ Loader WordPress plugin before 1.4.1 does not enforce nonce checks, which allows attackers to make administrators delete arbitrary loaders via a CSRF attack

CVE-2021-24199
wpDataTables – Tables & Table Charts Web Database Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-89 1 PoC

The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user to perform Boolean-based blind SQL Injection in the table list page on the endpoint /wp-admin/admin-ajax.php?action=get_wdtable&table_id=1, on the 'start' HTTP POST parameter. This allows an attacker to access all the data in the database and obtain access to the WordPress application.

CVE-2021-37164
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. In the tcpTxThread function, the received data is copied to a stack buffer. An off-by-3 condition can occur, resulting in a stack-based buffer overflow.

CVE-2021-45092
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.4%
2021 1 PoC

Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection via the vpath parameter.

CVE-2021-38834
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.