7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24670
CoolClock – a Javascript Analog Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

CVE-2021-31885
APOGEE MBC (PPC) (BACnet) General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-805 1 PoC

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V

CVE-2021-41282
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
91.3%
2021 2 PoCs

diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data about the routes set in the firewall. The data is retrieved by executing the netstat utility, and then its output is parsed via the sed utility. Although the common protection mechanisms against command injection (i.e., the usage of the escapeshellarg function for the arguments) are used, it is still possible to inject sed-specific code and write an arbitrary file in an arbitrary location.

CVE-2021-24953
Advanced iFrame Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Advanced iFrame WordPress plugin before 2022 does not sanitise and escape the ai_config_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-46426
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functionality.

CVE-2021-46385
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

CVE-2021-45980
Software Genérico Web
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the JavaScript API.

CVE-2021-37403
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

OX App Suite before 7.10.3-rev32 and 7.10.4 before 7.10.4-rev18 allows XSS via a code snippet (user-generated content) when a sharing link is created and an App Loader relative URL is used.

CVE-2021-24226
AccessAlly Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
25.4%
2021 CWE-200 1 PoC

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

CVE-2021-42682
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-24205
Elementor Website Builder Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

In the Elementor Website Builder WordPress plugin before 3.1.4, the icon box widget (includes/widgets/icon-box.php) accepts a ‘title_size’ parameter. Although the element control lists a fixed set of possible html tags, it is possible for a user with Contributor or above permissions to send a modified ‘save_builder’ request containing JavaScript in the ‘title_size’ parameter, which is not filtered and is output without escaping. This JavaScript will then be executed when the saved page is viewed or previewed.

CVE-2021-37613
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service.

CVE-2021-35491
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via the /enginemanager/server/user/delete.htm userName parameter. The application does not implement a CSRF token for the GET request. This issue was resolved in Wowza Streaming Engine release 4.8.14.

CVE-2021-32305
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2021 2 PoCs

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

CVE-2021-35053
Kaspersky Endpoint Security for Windows Windows
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

Possible system denial of service in case of arbitrary changing Firefox browser parameters. An attacker could change specific Firefox browser parameters file in a certain way and then reboot the system to make the system unbootable.

CVE-2021-32156
Software Genérico Web
N/A
UNKNOWN
EPSS
8.0%
2021 1 PoC

A cross-site request forgery (CSRF) vulnerability exists in Webmin 1.973 via the Scheduled Cron Jobs feature.

CVE-2021-20070
Racom MIDGE Firmware Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via the virtualization.php dialogs.

CVE-2021-25299
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
85.2%
2021 1 PoC

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

CVE-2021-23841
OpenSSL Web
N/A
UNKNOWN
EPSS
1.0%
2021 11 PoCs

The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently result in a NULL pointer deref and a crash leading to a potential denial of service attack. The function X509_issuer_and_serial_hash() is never directly called by OpenSSL itself so applications are only vulnerable if they use this fun