9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-33550
E2 Series General
7.2
HIGH
EPSS
86.6%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-33534
IE-WL(T)-BL-AP-CL-XX General
7.2
HIGH
EPSS
3.7%
2021 CWE-78 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.

CVE-2021-33539
IE-WL(T)-BL-AP-CL-XX General
7.2
HIGH
EPSS
0.4%
2021 CWE-287 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

CVE-2021-36296
VNX Control Station General
7.2
HIGH
EPSS
0.9%
2021 CWE-78 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

CVE-2021-29439
grav-plugin-admin General
7.2
HIGH
EPSS
0.7%
2021 CWE-863 1 PoC

The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin, an attacker can obtain an arbitrary code execution primitive and elevate their privileges on the instance. The vulnerability has been addressed in version 1.10.11. As a mitigation blocking access to the `/admin` path from untrusted sources will reduce the probability of exploitation.

CVE-2021-42383
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

CVE-2021-28203
BMC firmware for Z10PR-D16 General
7.2
HIGH
EPSS
1.7%
2021 CWE-78 1 PoC

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

CVE-2021-25479
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.2%
2021 CWE-122 1 PoC

A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-33548
E2 Series General
7.2
HIGH
EPSS
87.4%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-21573
BIOSConnect General
7.2
HIGH
EPSS
0.0%
2021 CWE-121 1 PoC

Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.

CVE-2021-33553
E2 Series General
7.2
HIGH
EPSS
84.0%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-22900
🔥 KEV Pulse Secure Secure General
7.2
HIGH
EPSS
0.7%
2021 CWE-94 1 PoC

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CVE-2021-33545
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the counter parameter which may allow an attacker to remotely execute arbitrary code.

CVE-2021-33546
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the name parameter, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42378
busybox General
7.2
HIGH
EPSS
0.2%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

CVE-2021-33549
E2 Series General
7.2
HIGH
EPSS
88.7%
2021 CWE-121 2 PoCs

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-33544
E2 Series General ⚡ nuclei
7.2
HIGH
EPSS
94.2%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42380
busybox General
7.2
HIGH
EPSS
0.5%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

CVE-2021-39115
Jira Service Desk Server General
7.2
HIGH
EPSS
25.7%
2021 CWE-96 1 PoC

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

CVE-2021-36295
VNX Control Station General
7.2
HIGH
EPSS
0.9%
2021 CWE-78 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.