7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-46398
Software Genérico Web
N/A
UNKNOWN
EPSS
10.3%
2021 7 PoCs

A Cross-Site Request Forgery vulnerability exists in Filebrowser < 2.18.0 that allows attackers to create a backdoor user with admin privilege and get access to the filesystem via a malicious HTML webpage that is sent to the victim. An admin can run commands using the FileBrowser and hence it leads to RCE.

CVE-2021-38378
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a person's name.

CVE-2021-38503
Firefox General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVE-2021-45088
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.

CVE-2021-37805
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.

CVE-2021-3199
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2021 2 PoCs

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

CVE-2021-45998
Software Genérico General
N/A
UNKNOWN
EPSS
5.8%
2021 1 PoC

D-Link device DIR_882 DIR_882_FW1.30B06_Hotfix_02 was discovered to contain a command injection vulnerability in the LocalIPAddress parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

CVE-2021-1629
Tableau General
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.

CVE-2021-37331
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uploading an ID Card or Trade License and viewing it, ID Cards and Trade Licenses of other vendors/users can be viewed by changing the URL.

CVE-2021-36696
Software Genérico Web Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.

CVE-2021-36760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

In accountrecoveryendpoint/recoverpassword.do in WSO2 Identity Server 5.7.0, it is possible to perform a DOM-Based XSS attack affecting the callback parameter modifying the URL that precedes the callback parameter. Once the username or password reset procedure is completed, the JavaScript code will be executed. (recoverpassword.do also has an open redirect issue for a similar reason.)

CVE-2021-42574
Software Genérico General
N/A
UNKNOWN
EPSS
25.0%
2021 6 PoCs

An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the

CVE-2021-46383
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

CVE-2021-27193
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.

CVE-2021-29387
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.

CVE-2021-22018
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

CVE-2021-43006
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

AmZetta Amzetta zPortal DVM Tools is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal DVM Tools <= v3.3.148.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-47760
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-20092
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 General ⚡ nuclei
N/A
UNKNOWN
EPSS
68.8%
2021 1 PoC

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

CVE-2021-3544
QEMU General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-401 1 PoC

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.