3303 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2007-2032
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.4%
2007 1 PoC

Cisco Wireless Control System (WCS) before 4.0.96.0 has a hard-coded FTP username and password for backup operations, which allows remote attackers to read and modify arbitrary files via unspecified vectors related to "properties of the FTP server," aka Bug ID CSCse93014.

CVE-2007-6233
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.2%
2007 1 PoC

Directory traversal vulnerability in index.php in FTP Admin 0.1.0 allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

CVE-2014-6032
Software Genérico Networking
N/A
UNKNOWN
EPSS
2.5%
2014 1 PoC

Multiple XML External Entity (XXE) vulnerabilities in the Configuration utility in F5 BIG-IP LTM, ASM, GTM, and Link Controller 11.0 through 11.6.0 and 10.0.0 through 10.2.4, AAM 11.4.0 through 11.6.0, ARM 11.3.0 through 11.6.0, Analytics 11.0.0 through 11.6.0, APM and Edge Gateway 11.0.0 through 11.6.0 and 10.1.0 through 10.2.4, PEM 11.3.0 through 11.6.0, PSM 11.0.0 through 11.4.1 and 10.0.0 through 10.2.4, and WOM 11.0.0 through 11.3.0 and 10.0.0 through 10.2.4 and Enterprise Manager 3.0.0 through 3.1.1 and 2.1.0 through 2.3.0 allow remote authenticated users to read arbitrary files and caus

CVE-2015-2676
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.2%
2015 1 PoC

Cross-site request forgery (CSRF) vulnerability in the ASUS RT-G32 routers with firmware 2.0.2.6 and 2.0.3.2 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to start_apply.htm.

CVE-2021-43729
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Pix-Link MiNi Router 28K.MiniRouter.20190211 was discovered to contain a stored cross-site scripting (XSS) vulnerability due to an unsanitized Security Key parameter.

CVE-2021-28041
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.

CVE-2021-27691
Software Genérico Networking
N/A
UNKNOWN
EPSS
4.4%
2021 2 PoCs

Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows remote attackers to execute arbitrary OS commands via a crafted action/setDebugCfg request. This occurs because the "formSetDebugCfg" function executes glibc's system function with untrusted input.

CVE-2015-8362
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
2.7%
2015 2 PoCs

The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984.

CVE-2021-40847
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
5.4%
2021 2 PoCs

The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve remote code execution as root via a MitM attack. While the parental controls themselves are not enabled by default on the routers, the Circle update daemon, circled, is enabled by default. This daemon connects to Circle and NETGEAR to obtain version information and updates to the circled daemon and its filtering database. However, database updates from NETGEAR are unsigned and downloaded via cleartext HTTP. As such, an attacker with the ability to perform a MitM attack on the

CVE-2021-20031
SonicOS Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
36.2%
2021 CWE-601 1 PoC

A Host Header Redirection vulnerability in SonicOS potentially allows a remote attacker to redirect firewall management users to arbitrary web domains.

CVE-2014-4977
Software Genérico Web Networking Database
N/A
UNKNOWN
EPSS
84.5%
2014 3 PoCs

Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) selectedUserGroup parameter in a create new user request to cgi-bin/admin.cgi or the (2) user_id parameter in the changeUnit function, (3) methodDetail parameter in the methodDetail function, or (4) xcNetworkDetail parameter in the xcNetworkDetail function in d4d/exporters.php.

CVE-2021-33962
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.

CVE-2021-24956
Blog2Social: Social Media Auto Post & Scheduler Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2021 CWE-79 1 PoC

The Blog2Social: Social Media Auto Post & Scheduler WordPress plugin before 6.8.7 does not sanitise and escape the b2sShowByDate parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-33963
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
4.0%
2021 1 PoC

China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.

CVE-2021-31152
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
1.4%
2021 2 PoCs

Multilaser Router AC1200 V02.03.01.45_pt contains a cross-site request forgery (CSRF) vulnerability. An attacker can enable remote access, change passwords, and perform other actions through misconfigured requests, entries, and headers.

CVE-2015-2683
Software Genérico Networking
N/A
UNKNOWN
EPSS
3.3%
2015 2 PoCs

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX) Servlet, which allows remote attackers to execute arbitrary code via unspecified vectors to servlets/Jmx_dynamic.

CVE-2003-1096
Software Genérico Networking
N/A
UNKNOWN
EPSS
54.5%
2003 1 PoC

The Cisco LEAP challenge/response authentication mechanism uses passwords in a way that is susceptible to dictionary attacks, which makes it easier for remote attackers to gain privileges via brute force password guessing attacks.

CVE-2003-0106
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.7%
2003 2 PoCs

The HTTP proxy for Symantec Enterprise Firewall (SEF) 7.0 allows proxy users to bypass pattern matching for blocked URLs via requests that are URL-encoded with escapes, Unicode, or UTF-8.

CVE-2003-1132
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.5%
2003 1 PoC

The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS servers to send and cache a request for a AAAA record to the vulnerable server.

CVE-2003-0260
Software Genérico Networking
N/A
UNKNOWN
EPSS
1.6%
2003 1 PoC

Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7A allow remote attackers to cause a denial of service (slowdown and possibly reload) via a flood of malformed ICMP packets.