7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24702
LearnPress – WordPress LMS Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The LearnPress WordPress plugin before 4.1.3.1 does not properly sanitize or escape various inputs within course settings, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltred_html capability is disallowed

CVE-2021-44736
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

The initial admin account setup wizard on Lexmark devices allow unauthenticated access to the “out of service erase” feature.

CVE-2021-24862
RegistrationMagic – Custom Registration Forms, User Registration and User Login Plugin Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
34.8%
2021 CWE-89 2 PoCs

The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action before using it in a SQL statement when duplicating tasks in batches, which could lead to a SQL injection issue

CVE-2021-40104
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.

CVE-2021-40096
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A cross-site scripting (XSS) vulnerability in integration configuration in SquaredUp for SCOM 5.2.1.6654 allows remote attackers to inject arbitrary web script or HTML via modification of the authorisationUrl in some integration configurations.

CVE-2021-43461
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.

CVE-2021-24318
Listeo Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-284 2 PoCs

The Listeo WordPress theme before 1.6.11 did not ensure that the Post/Page and Booking to delete belong to the user making the request, allowing any authenticated users to delete arbitrary page/post and booking via an IDOR vector.

CVE-2021-26314
All supported processors General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-208 1 PoC

Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.

CVE-2021-24775
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The Document Embedder WordPress plugin before 1.7.5 contains a REST endpoint, which could allow unauthenticated users to enumerate the title of arbitrary private and draft posts.

CVE-2021-24128
Team Members Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the Team Members WordPress plugin, versions before 5.0.4, lead to Cross-site scripting vulnerabilities allowing medium-privileged authenticated attacker (contributor+) to inject arbitrary web script or HTML via the 'Description/biography' of a member.

CVE-2021-41950
Software Genérico Web
N/A
UNKNOWN
EPSS
32.3%
2021 1 PoC

A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete arbitrary files on the ResourceSpace server via the provider and variant parameters in pages/ajax/tiles.php. Attackers can delete configuration or source code files, causing the application to become unavailable to all users.

CVE-2021-43456
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the RumbleService executable service path.

CVE-2021-24958
Meks Easy Photo Feed Widget Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF checks in the meks_save_business_selected_account AJAX action, available to any authenticated user, and does not escape some of the settings. As a result, any authenticated user, such as subscriber could update the plugin's settings and put Cross-Site Scripting payloads in them

CVE-2021-41449
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.

CVE-2021-33469
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.

CVE-2021-36165
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

RICON Industrial Cellular Router S9922L 16.10.3(3794) is affected by cleartext storage of sensitive information and sends username and password as base64.

CVE-2021-31762
Software Genérico Web
N/A
UNKNOWN
EPSS
22.7%
2021 4 PoCs

Webmin 1.973 is affected by Cross Site Request Forgery (CSRF) to create a privileged user through Webmin's add users feature, and then get a reverse shell through Webmin's running process feature.

CVE-2021-44879
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.

CVE-2021-37748
Software Genérico General
N/A
UNKNOWN
EPSS
11.9%
2021 2 PoCs

Multiple buffer overflows in the limited configuration shell (/sbin/gs_config) on Grandstream HT801 devices before 1.0.29 allow remote authenticated users to execute arbitrary code as root via a crafted manage_if setting, thus bypassing the intended restrictions of this shell and taking full control of the device. There are default weak credentials that can be used to authenticate.

CVE-2021-25111
English WordPress Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.8%
2021 CWE-601 1 PoC

The English WordPress Admin WordPress plugin before 1.5.2 does not validate the admin_custom_language_return_url before redirecting users o it, leading to an open redirect issue