1712 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-33972
Software Genérico General
10.0
CRITICAL
EPSS
0.5%
2021 2 PoCs

Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.

CVE-2021-38516
Software Genérico General
10.0
CRITICAL
EPSS
0.5%
2021 1 PoC

Certain NETGEAR devices are affected by lack of access control at the function level. This affects D6220 before 1.0.0.48, D6400 before 1.0.0.82, D7000v2 before 1.0.0.52, D7800 before 1.0.1.44, D8500 before 1.0.3.43, DC112A before 1.0.0.40, DGN2200v4 before 1.0.0.108, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBR40 before 2.3.0.28, RBS40 before 2.3.0.28, R6020 before 1.0.0.34, R6080 before 1.0.0.34, R6120 before 1.0.0.44, R6220 before 1.1.0.80, R6230 before 1.1.0.80, R6250 befo

CVE-2021-40393
Gerbv General
10.0
CRITICAL
EPSS
0.4%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-40422
Swift Sensors Gateway General
10.0
CRITICAL
EPSS
11.0%
2021 CWE-798 1 PoC

An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-40419
Software Genérico General
10.0
CRITICAL
EPSS
0.5%
2021 CWE-489 1 PoC

A firmware update vulnerability exists in the 'factory' binary of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted series of network requests can lead to arbitrary firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-33975
Software Genérico General
10.0
CRITICAL
EPSS
0.3%
2021 2 PoCs

Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges.

CVE-2021-41269
cron-utils General
10.0
CRITICAL
EPSS
1.9%
2021 CWE-94 1 PoC

cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no kno

CVE-2021-21951
Anker General
10.0
CRITICAL
EPSS
0.9%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.

CVE-2021-21940
Anker General
10.0
CRITICAL
EPSS
0.5%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-40391
Gerbv General
10.0
CRITICAL
EPSS
0.5%
2021 CWE-390 1 PoC

An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-41277
🔥 KEV metabase General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-200 13 PoCs

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the applicat

CVE-2021-21820
D-Link General
10.0
CRITICAL
EPSS
2.0%
2021 CWE-798 1 PoC

A hard-coded password vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-21913
D-Link General
10.0
CRITICAL
EPSS
0.7%
2021 CWE-798 1 PoC

An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specially-crafted network request can lead to command execution. An attacker can connect to the MQTT service to trigger this vulnerability.

CVE-2021-40394
Gerbv General
10.0
CRITICAL
EPSS
0.6%
2021 1 PoC

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-33970
Software Genérico General
10.0
CRITICAL
EPSS
2.0%
2021 2 PoCs

Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.

CVE-2021-21950
Anker General
10.0
CRITICAL
EPSS
0.9%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution.

CVE-2021-21961
Sealevel General
10.0
CRITICAL
EPSS
2.3%
2021 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-43936
WebHMI General
10.0
CRITICAL
EPSS
28.4%
2021 2 PoCs

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

CVE-2021-40401
Gerbv General
10.0
CRITICAL
EPSS
0.4%
2021 CWE-252 1 PoC

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-20998
0852-0303 General
10.0
CRITICAL
EPSS
0.1%
2021 CWE-306 1 PoC

In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.