7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-45348
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).

CVE-2021-24688
Orange Form Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-284 1 PoC

The Orange Form WordPress plugin through 1.0.1 does not have any authorisation and CSRF checks in all of its AJAX calls, for example the or_delete_filed one which is available to both unauthenticated and authenticated users could allow attackers to delete arbitrary posts.The AJAX calls performing actions on posts also do not ensure that the post belong to them (or that they are allowed to perform such action on it)

CVE-2021-24784
WP Admin Logo Changer Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.

CVE-2021-3602
buildah DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-200 1 PoC

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent processes. When run in a container in a CI/CD environment, environment variables may include sensitive information that was shared with the container in order to be used only by Buildah itself (e.g. container registry credentials).

CVE-2021-38377
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because there is a predictable UUID with HTML transformation results.

CVE-2021-20114
TCExam General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.9%
2021 0 PoCs

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.

CVE-2021-37589
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
77.7%
2021 2 PoCs

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVE-2021-39298
2nd Gen EPYC General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.

CVE-2021-35956
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2021 3 PoCs

Stored cross-site scripting (XSS) in the embedded webserver of AKCP sensorProbe before SP480-20210624 enables remote authenticated attackers to introduce arbitrary JavaScript via the Sensor Description, Email (from/to/cc), System Name, and System Location fields.

CVE-2021-26329
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-130 1 PoC

AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.

CVE-2021-25415
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-94 1 PoC

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.

CVE-2021-43457
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service path.

CVE-2021-25791
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 3 PoCs

Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

CVE-2021-29388
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Title'.

CVE-2021-37548
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.

CVE-2021-27928
Software Genérico Database
N/A
UNKNOWN
EPSS
48.9%
2021 5 PoCs

A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.

CVE-2021-46888
Software Genérico Web
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function.

CVE-2021-3229
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Denial of service in ASUSWRT ASUS RT-AX3000 firmware versions 3.0.0.4.384_10177 and earlier versions allows an attacker to disrupt the use of device setup services via continuous login error.

CVE-2021-26717
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certified Asterisk before 16.8-cert6. When re-negotiating for T.38, if the initial remote response was delayed just enough, Asterisk would send both audio and T.38 in the SDP. If this happened, and the remote responded with a declined T.38 stream, then Asterisk would crash.