878 vulnerabilidades · General · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-20114
TCExam General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.9%
2021 0 PoCs

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.

CVE-2021-46417
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.2%
2021 4 PoCs

Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.

CVE-2021-20158
Trendnet AC2600 TEW-827DRU General ⚡ nuclei
N/A
UNKNOWN
EPSS
86.4%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an authentication bypass vulnerability. It is possible for an unauthenticated, malicous actor to force the change of the admin password due to a hidden administrative command.

CVE-2021-46424
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2021 1 PoC

Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

CVE-2021-36580
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2021 2 PoCs

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

CVE-2021-35336
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
85.8%
2021 1 PoC

Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.

CVE-2021-29203
HPE Edgeline Infrastructure Management Software General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 0 PoCs

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

CVE-2021-20617
acmailer and acmailer DB General ⚡ nuclei
N/A
UNKNOWN
EPSS
62.4%
2021 0 PoCs

Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive information on the server via unspecified vectors.

CVE-2021-32305
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
92.4%
2021 2 PoCs

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

CVE-2021-20092
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 General ⚡ nuclei
N/A
UNKNOWN
EPSS
68.8%
2021 1 PoC

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

CVE-2023-37679
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.4%
2023 2 PoCs

A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server.

CVE-2021-45420
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.3%
2021 1 PoC

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced

CVE-2021-37292
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.

CVE-2021-31324
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

CVE-2021-3297
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2021 0 PoCs

On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.

CVE-2021-46107
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
67.2%
2021 0 PoCs

Ligeo Archives Ligeo Basics as of 02_01-2022 is vulnerable to Server Side Request Forgery (SSRF) which allows an attacker to read any documents via the download features.

CVE-2021-27964
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
82.1%
2021 1 PoC

SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Config/SaveUploadedHotspotLogoFile without any authentication or session header. There is no check for the file extension or content of the uploaded file.

CVE-2021-45027
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
17.4%
2021 1 PoC

An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via the FileServlet function allows for arbitrary file download by an attacker using unsanitized user supplied input.