9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-41192
redash General ⚡ nuclei
8.1
HIGH
EPSS
79.6%
2021 CWE-1188 0 PoCs

Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without explicitly specifying the `REDASH_COOKIE_SECRET` or `REDASH_SECRET_KEY` environment variables, a default value is used for both that is the same across all installations. In such cases, the instance is vulnerable to attackers being able to forge sessions using the known default value. This issue only affects installations where the `REDASH_COOKIE_SECRET or REDASH_SECRET_KEY` environment variables have not been explicitly set. This issue does not affect users of the official Reda

CVE-2021-21772
3MF General
8.1
HIGH
EPSS
1.7%
2021 2 PoCs

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-23406
pac-resolver General
8.1
HIGH
EPSS
1.0%
2021 2 PoCs

This affects the package pac-resolver before 5.0.0. This can occur when used with untrusted input, due to unsafe PAC file handling. **NOTE:** The fix for this vulnerability is applied in the node-degenerator library, a dependency written by the same maintainer.

CVE-2021-20190
jackson-databind General
8.1
HIGH
EPSS
0.5%
2021 CWE-502 1 PoC

A flaw was found in jackson-databind before 2.9.10.7. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2021-40680
Software Genérico General
8.1
HIGH
EPSS
0.4%
2021 1 PoC

There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.

CVE-2021-23758
AjaxPro.2 General
8.1
HIGH
EPSS
87.8%
2021 3 PoCs

All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.

CVE-2021-21824
Accusoft General
8.1
HIGH
EPSS
0.4%
2021 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-43449
Software Genérico General
8.1
HIGH
EPSS
0.8%
2021 1 PoC

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor service can be abused to read and serve arbitrary URLs as a document.

CVE-2021-46143
Software Genérico General
8.1
HIGH
EPSS
4.1%
2021 2 PoCs

In doProlog in xmlparse.c in Expat (aka libexpat) before 2.4.3, an integer overflow exists for m_groupSize.

CVE-2021-21826
AT&T General
8.1
HIGH
EPSS
0.5%
2021 CWE-120 1 PoC

A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xmill 0.7. Within `DecodeTreeBlock` which is called during the decompression of an XMI file, a UINT32 is loaded from the file and used as trusted input as the length of a buffer. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-21810
AT&T Labs General
8.1
HIGH
EPSS
0.6%
2021 CWE-122 1 PoC

A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-23412
gitlogplus General
8.1
HIGH
EPSS
4.4%
2021 1 PoC

All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

CVE-2021-3460
MH702x General
8.1
HIGH
EPSS
0.2%
2021 CWE-295 1 PoC

The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.

CVE-2021-37500
Software Genérico General
8.1
HIGH
EPSS
0.7%
2021 1 PoC

Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.

CVE-2021-21811
AT&T General
8.1
HIGH
EPSS
0.6%
2021 CWE-191 1 PoC

A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-36801
Akaunting General
8.1
HIGH
EPSS
0.3%
2021 CWE-639 1 PoC

Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, companies[0]. This issue was fixed in version 2.1.13 of the product.

CVE-2021-21829
AT&T General
8.1
HIGH
EPSS
2.3%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-36330
Dell EMC Streaming Data Platform General
8.1
HIGH
EPSS
0.9%
2021 CWE-613 1 PoC

Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to reuse old session artifacts to impersonate a legitimate user.

CVE-2021-21479
SCIMono General ⚡ nuclei
8.1
HIGH
EPSS
78.2%
2021 0 PoCs

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

CVE-2021-33705
SAP NetWeaver Enterprise Portal General
8.1
HIGH
EPSS
0.7%
2021 CWE-918 1 PoC

The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a user can make any type of request (e.g. POST, GET) to any internal or external server. This can result in the accessing or modification of data accessible from the Portal but will not affect its availability.