3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-27253
R7800 General
8.8
HIGH
EPSS
0.7%
2021 CWE-122 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the rc_service parameter provided to apply_bind.cgi. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12303.

CVE-2021-3855
Liman Central Management System Web
8.8
HIGH
EPSS
1.5%
2021 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection.This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462.

CVE-2021-43810
admidio Web ⚡ nuclei
8.8
HIGH
EPSS
70.9%
2021 CWE-79 0 PoCs

Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vulnerability is present in Admidio prior to version 4.0.12. The Reflected XSS vulnerability occurs because redirect.php does not properly validate the value of the url parameter. Through this vulnerability, an attacker is capable to execute malicious scripts. This issue is patched in version 4.0.12.

CVE-2021-24093
Windows 10 Version 1803 Windows
8.8
HIGH
EPSS
28.5%
2021 1 PoC

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2021-21893
Foxit Web
8.8
HIGH
EPSS
1.0%
2021 CWE-416 1 PoC

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.0.0.49893. A specially crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled.

CVE-2021-34602
CC612 General
8.8
HIGH
EPSS
3.4%
2021 CWE-78 1 PoC

In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.

CVE-2021-22899
🔥 KEV Pulse Connect Secure Windows
8.8
HIGH
EPSS
15.9%
2021 CWE-77 1 PoC

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

CVE-2021-2392
BI Publisher (formerly XML Publisher) Web Database
8.8
HIGH
EPSS
3.5%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2021-47848
Aplikasi-Biro-Travel Database
8.8
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative access.

CVE-2021-21835
GPAC Project General
8.8
HIGH
EPSS
0.4%
2021 CWE-680 1 PoC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom associated with the “csgp” FOURCC can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-25966
Users Web
8.8
HIGH
EPSS
0.3%
2021 CWE-613 1 PoC

In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

CVE-2021-38003
🔥 KEV Chrome General
8.8
HIGH
EPSS
65.7%
2021 2 PoCs

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30551
🔥 KEV Chrome General
8.8
HIGH
EPSS
78.4%
2021 1 PoC

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-31837
McAfee GetSusp General
8.8
HIGH
EPSS
0.1%
2021 CWE-787 1 PoC

Memory corruption vulnerability in the driver file component in McAfee GetSusp prior to 4.0.0 could allow a program being investigated on the local machine to trigger a buffer overflow in GetSusp, leading to the execution of arbitrary code, potentially triggering a BSOD.

CVE-2021-40399
WPS Office General
8.8
HIGH
EPSS
0.7%
2021 CWE-416 1 PoC

An exploitable use-after-free vulnerability exists in WPS Spreadsheets ( ET ) as part of WPS Office, version 11.2.0.10351. A specially-crafted XLS file can cause a use-after-free condition, resulting in remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability.

CVE-2021-40388
Software Genérico General
8.8
HIGH
EPSS
0.0%
2021 CWE-276 1 PoC

A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-28825
TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The Windows Installation component of TIBCO Software Inc.'s TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Community Edition and TIBCO Messaging - Eclipse Mosquitto Distribution - Core - Enterprise Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system to insert malicious software. The affected component can be abused to execute the malicious software inserted by the attacker with the elevated privileges of the component. This vulnerability results from a lack of access restrictions on c

CVE-2021-2391
BI Publisher (formerly XML Publisher) Web Database
8.8
HIGH
EPSS
4.8%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Scheduler). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).