63 vulnerabilidades · 🔥 KEV · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2021-28799
🔥 KEV HBS 3 Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
90.8%
2021 CWE-285 0 PoCs

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

CVE-2021-30116
🔥 KEV Software Genérico Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
54.1%
2021 3 PoCs

Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x/dl.asp When an attacker download a client for Windows and installs it, the file KaseyaD.ini is generated (C:\Program Files (x86)\Kaseya\XXXXXXXXXX\KaseyaD.ini) which contains an Agent_Guid and AgentPassword This Agent_Guid and AgentPassword can be used to log in on dl.asp (https://x.x.x.x/dl.asp?un=840997037507813&pw=113cc622839a4077a84837485

CVE-2021-44228
🔥 KEV Apache Log4j2 Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-502 276 PoCs

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnera

CVE-2021-22205
🔥 KEV GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
94.5%
2021 34 PoCs

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

CVE-2021-41277
🔥 KEV metabase General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-200 13 PoCs

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the applicat

CVE-2021-33045
🔥 KEV Some Dahua IP Camera, Video Intercom, NVR, XVR devices General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2021 3 PoCs

The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets.

CVE-2021-20021
🔥 KEV Email Security Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2021 CWE-269 1 PoC

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

CVE-2021-44077
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2021 3 PoCs

Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 are vulnerable to unauthenticated remote code execution. This is related to /RestAPI URLs in a servlet, and ImportTechnicians in the Struts configuration.

CVE-2021-42237
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 4 PoCs

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

CVE-2021-1498
🔥 KEV Cisco HyperFlex HX Data Platform Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2021 CWE-78 1 PoC

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2021-20090
🔥 KEV Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 2 PoCs

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

CVE-2021-36380
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
93.6%
2021 1 PoC

Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.

CVE-2021-42013
🔥 KEV Apache HTTP Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 CWE-22 51 PoCs

It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions.

CVE-2021-21985
🔥 KEV VMware vCenter Server and VMware Cloud Foundation Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 13 PoCs

The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.

CVE-2021-40870
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2021 8 PoCs

An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.

CVE-2021-1497
🔥 KEV Cisco HyperFlex HX Data Platform Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2021 CWE-78 1 PoC

Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2021-20038
🔥 KEV SonicWall SMA100 Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2021 CWE-121 3 PoCs

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated attacker to potentially execute code as a 'nobody' user in the appliance. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances firmware 10.2.0.8-37sv, 10.2.1.1-19sv, 10.2.1.2-24sv and earlier versions.

CVE-2021-44529
🔥 KEV Ivanti EPM Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2021 CWE-94 4 PoCs

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

CVE-2021-35587
🔥 KEV Access Manager Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2021 3 PoCs

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported versions that are affected are 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).