3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-21895
Lantronix Web
9.1
CRITICAL
EPSS
2.8%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-40411
Software Genérico Web
9.1
CRITICAL
EPSS
1.3%
2021 CWE-78 1 PoC

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_data->dns2 variable, that has the value of the dns2 parameter provided through the SetLocalLink API, is not validated properly. This would lead to an OS command injection.

CVE-2021-41097
path Web Networking ⚡ nuclei
9.1
CRITICAL
EPSS
11.7%
2021 CWE-1321 1 PoC

aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `

CVE-2021-4457
ZoomSounds Web
9.1
CRITICAL
EPSS
0.4%
2021 1 PoC

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.

CVE-2021-28500
Arista EOS Web
9.1
CRITICAL
EPSS
0.3%
2021 CWE-285 1 PoC

An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

CVE-2021-3850
adodb/adodb General
9.1
CRITICAL
EPSS
0.3%
2021 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

CVE-2021-43778
barcode Web ⚡ nuclei
9.1
CRITICAL
EPSS
90.4%
2021 CWE-22 2 PoCs

Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the barcode plugin installed are vulnerable to a path traversal vulnerability. This issue was patched in version 2.6.1. As a workaround, delete the `front/send.php` file.

CVE-2021-35495
TIBCO JasperReports Server Cloud
9.0
CRITICAL
EPSS
0.4%
2021 1 PoC

The Scheduler Connection component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows an authenticated attacker with network access to obtain FTP server passwords for other users of the affected system. Affected r

CVE-2021-43616
Software Genérico General
9.0
CRITICAL
EPSS
1.9%
2021 2 PoCs

The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to

CVE-2021-35493
TIBCO WebFOCUS Client Web
9.0
CRITICAL
EPSS
0.4%
2021 1 PoC

The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO WebF

CVE-2021-27635
SAP NetWeaver AS for JAVA General
9.0
CRITICAL
EPSS
2.1%
2021 1 PoC

SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.

CVE-2021-35211
🔥 KEV Serv-U Managed File Transfer Server and Serv-U Secured FTP Windows
9.0
CRITICAL
EPSS
94.3%
2021 4 PoCs

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 are affected by this vulnerability.

CVE-2021-21962
Sealevel General
9.0
CRITICAL
EPSS
2.3%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-in-the-middle attack in order to trigger this vulnerability.

CVE-2021-25384
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.2%
2021 CWE-122 1 PoC

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-34523
🔥 KEV Microsoft Exchange Server 2013 Cumulative Update 23 Windows
9.0
CRITICAL
EPSS
94.0%
2021 2 PoCs

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2021-25386
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.2%
2021 CWE-121 1 PoC

An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

CVE-2021-33351
Software Genérico General
9.0
CRITICAL
EPSS
0.4%
2021 1 PoC

Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.

CVE-2021-23885
McAfee Web Gateway (MWG) General
9.0
CRITICAL
EPSS
0.9%
2021 CWE-269 1 PoC

Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain elevated privileges through the User Interface and execute commands on the appliance via incorrect improper neutralization of user input in the troubleshooting page.

CVE-2021-1924
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
9.0
CRITICAL
EPSS
0.0%
2021 1 PoC

Information disclosure through timing and power side-channels during mod exponentiation for RSA-CRT in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2021-25385
Samsung Mobile Devices General
9.0
CRITICAL
EPSS
0.2%
2021 CWE-121 1 PoC

An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.