2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-42379
busybox General
7.2
HIGH
EPSS
0.2%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

CVE-2021-42385
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

CVE-2021-42380
busybox General
7.2
HIGH
EPSS
0.5%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function

CVE-2021-46850
Software Genérico Web
7.2
HIGH
EPSS
12.5%
2021 1 PoC

myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when sending HTTP POST requests to the /edit/server endpoint.

CVE-2021-33534
IE-WL(T)-BL-AP-CL-XX General
7.2
HIGH
EPSS
3.7%
2021 CWE-78 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrary system commands, resulting in full control of the device. An attacker can send various requests while authenticated as a high privilege user to trigger this vulnerability.

CVE-2021-24151
WP Editor Web Database Windows
7.2
HIGH
EPSS
0.5%
2021 1 PoC

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

CVE-2021-24942
Menu Item Visibility Control Web Windows
7.2
HIGH
EPSS
1.0%
2021 1 PoC

The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.

CVE-2021-33539
IE-WL(T)-BL-AP-CL-XX General
7.2
HIGH
EPSS
0.4%
2021 CWE-287 1 PoC

In Weidmueller Industrial WLAN devices in multiple versions an exploitable authentication bypass vulnerability exists in the hostname processing. A specially configured device hostname can cause the device to interpret selected remote traffic as local traffic, resulting in a bypass of web authentication. An attacker can send authenticated SNMP requests to trigger this vulnerability.

CVE-2021-36296
VNX Control Station General
7.2
HIGH
EPSS
0.9%
2021 CWE-78 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

CVE-2021-29439
grav-plugin-admin General
7.2
HIGH
EPSS
0.7%
2021 CWE-863 1 PoC

The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin, an attacker can obtain an arbitrary code execution primitive and elevate their privileges on the instance. The vulnerability has been addressed in version 1.10.11. As a mitigation blocking access to the `/admin` path from untrusted sources will reduce the probability of exploitation.

CVE-2021-39115
Jira Service Desk Server General
7.2
HIGH
EPSS
25.7%
2021 CWE-96 1 PoC

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

CVE-2021-36295
VNX Control Station General
7.2
HIGH
EPSS
0.9%
2021 CWE-78 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

CVE-2021-32670
datasette Web
7.2
HIGH
EPSS
0.6%
2021 CWE-79 2 PoCs

Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette does not correctly escape generated HTML, resulting in a [reflected cross-site scripting](https://owasp.org/www-community/attacks/xss/#reflected-xss-attacks) vulnerability. This vulnerability is particularly relevant if your Datasette installation includes authenticated features using plugins such as [datasette-auth-passwords](https://datasette.io/plugins/datasette-auth-passwords) as an attacker could use the vulnerability to access protected data. Datasette 0.57 and 0.56.1

CVE-2021-30166
P2/Z2/P3/Z3 IP camera firmware General
7.2
HIGH
EPSS
6.6%
2021 CWE-78 1 PoC

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

CVE-2021-24786
Download Monitor Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
2.2%
2021 CWE-89 1 PoC

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

CVE-2021-42383
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

CVE-2021-2328
Text Database
7.2
HIGH
EPSS
1.4%
2021 1 PoC

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2021-33547
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42382
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVE-2021-25478
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.2%
2021 CWE-121 1 PoC

A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.