2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25992
ifme General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-613 1 PoC

In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.

CVE-2021-23344
total.js General
9.8
CRITICAL
EPSS
12.7%
2021 1 PoC

The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set.

CVE-2021-21807
Accusoft General
9.8
CRITICAL
EPSS
0.5%
2021 CWE-190 1 PoC

An integer overflow vulnerability exists in the DICOM parse_dicom_meta_info functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to a stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-23803
latte/latte General
9.8
CRITICAL
EPSS
0.4%
2021 1 PoC

This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.

CVE-2021-42237
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 4 PoCs

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

CVE-2021-42777
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2021 2 PoCs

Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code on any machine that renders a report, including the application server or a user's local machine, as demonstrated by System.Diagnostics.Process.Start.

CVE-2021-1916
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-36294
VNX Control Station General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-331 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthenticated attacker may exploit this vulnerability by forging a cookie to login as any user.

CVE-2021-1919
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-33353
Software Genérico General
9.8
CRITICAL
EPSS
1.9%
2021 1 PoC

Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.

CVE-2021-25916
patchmerge General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-46760
3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT General
9.8
CRITICAL
EPSS
0.3%
2021 1 PoC

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.

CVE-2021-34569
750-81xx/xxx-xxxFW General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-787 1 PoC

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

CVE-2021-23390
total4 General
9.8
CRITICAL
EPSS
1.3%
2021 1 PoC

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

CVE-2021-23389
total.js General
9.8
CRITICAL
EPSS
5.3%
2021 1 PoC

The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

CVE-2021-26379
2nd Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

CVE-2021-27664
exacqVision Web Service General
9.8
CRITICAL
EPSS
0.3%
2021 CWE-269 1 PoC

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

CVE-2021-3836
dbeaver/dbeaver General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-611 1 PoC

dbeaver is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2021-23594
realms-shim General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.

CVE-2021-22502
🔥 KEV Operation Bridge Reporter. General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2021 1 PoC

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.