1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-30116
🔥 KEV Software Genérico Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
54.1%
2021 3 PoCs

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485

CVE-2021-44228
🔥 KEV Apache Log4j2 Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-502 276 PoCs

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnera

CVE-2021-40426
libsox Windows
10.0
CRITICAL
EPSS
0.5%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-4434
Social Sharing Plugin – Social Warfare Web Windows
10.0
CRITICAL
EPSS
8.0%
2021 CWE-94 1 PoC

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

CVE-2021-22893
🔥 KEV Pulse Connect Secure Windows
10.0
CRITICAL
EPSS
93.6%
2021 CWE-287 7 PoCs

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.

CVE-2021-4360
Controlled Admin Access Web Windows
9.9
CRITICAL
EPSS
0.1%
2021 CWE-284 1 PoC

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.

CVE-2021-28481
Microsoft Exchange Server 2019 Cumulative Update 9 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
34.4%
2021 0 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-4455
Wordpress Plugin Smart Product Review Web Windows
9.8
CRITICAL
EPSS
2.1%
2021 CWE-434 1 PoC

The Wordpress Plugin Smart Product Review plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2021-24649
WP User Frontend Web Windows
9.8
CRITICAL
EPSS
0.4%
2021 1 PoC

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin

CVE-2021-4380
Pinterest Automatic Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
81.3%
2021 CWE-284 0 PoCs

The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary options on a site that can be used to create new administrative user accounts or redirect unsuspecting site visitors.

CVE-2021-23274
TIBCO API Exchange Gateway Web Windows
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO API Exchange Gateway: versions 2.3.3 and below and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric: versions 2.3.3

CVE-2021-28480
Microsoft Exchange Server 2013 Cumulative Update 23 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
87.1%
2021 2 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-34624
ProfilePress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
68.3%
2021 CWE-434 0 PoCs

A vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible for users to upload arbitrary files during user registration or during profile updates. This issue affects versions 3.0.0 - 3.1.3. .

CVE-2021-34621
ProfilePress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2021 CWE-269 4 PoCs

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

CVE-2021-34622
ProfilePress Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
61.6%
2021 CWE-269 0 PoCs

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

CVE-2021-36888
Image Hover Effects Ultimate (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
68.3%
2021 CWE-284 0 PoCs

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

CVE-2021-4073
RegistrationMagic Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.0%
2021 CWE-287 0 PoCs

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

CVE-2021-4436
3DPrint Lite Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.9%
2021 1 PoC

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.