2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47888
Textpattern Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 1 PoC

Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.

CVE-2021-47701
OpenBMCS Web
8.7
HIGH
EPSS
0.1%
2021 CWE-862 2 PoCs

OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.

CVE-2021-47719
COMMAX WebViewer ActiveX Control General
8.7
HIGH
EPSS
0.1%
2021 CWE-787 2 PoCs

COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit boundary errors in Commax_WebViewer.ocx to cause buffer overflow conditions and potentially gain code execution.

CVE-2021-47713
Hasura GraphQL DevOps
8.7
HIGH
EPSS
0.2%
2021 CWE-770 1 PoC

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially crash the GraphQL endpoint.

CVE-2021-47849
Mini Mouse Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.

CVE-2021-4463
BEMS API Web
8.7
HIGH
EPSS
0.2%
2021 CWE-552 2 PoCs

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

CVE-2021-4466
IPCop General
8.7
HIGH
EPSS
0.4%
2021 CWE-78 1 PoC

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.

CVE-2021-47755
Oliver Library Server General
8.7
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.

CVE-2021-47705
COMMAX UMS Client ActiveX Control General
8.7
HIGH
EPSS
0.1%
2021 CWE-787 2 PoCs

COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and potentially gain system-level access.

CVE-2021-47741
ZBL EPON ONU Broadband Router Networking
8.7
HIGH
EPSS
0.1%
2021 CWE-522 2 PoCs

ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by sending requests to configuration endpoints. Attackers can exploit the vulnerability by accessing the configuration backup or password page to disclose the super user password and gain additional privileged functionalities.

CVE-2021-47904
PhreeBooks Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 2 PoCs

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

CVE-2021-47704
OpenBMCS Web Database
8.7
HIGH
EPSS
0.0%
2021 CWE-89 2 PoCs

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.

CVE-2021-47721
orangescrum General
8.7
HIGH
EPSS
0.0%
2021 CWE-639 1 PoC

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

CVE-2021-47795
GeoVision Geowebserver Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.

CVE-2021-47865
ProFTPD DevOps
8.7
HIGH
EPSS
0.0%
2021 CWE-770 1 PoC

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access.

CVE-2021-47711
Xperience Database
8.7
HIGH
EPSS
0.1%
2021 CWE-89 1 PoC

A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.

CVE-2021-47794
ZesleCP General
8.7
HIGH
EPSS
0.2%
2021 CWE-78 2 PoCs

ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FTP accounts with shell injection payloads. Attackers can exploit the FTP account creation endpoint by injecting a reverse shell command that establishes a network connection to a specified listening host.

CVE-2021-47710
Smart Home Ruvie CCTV Bridge DVR Service General
8.7
HIGH
EPSS
0.2%
2021 CWE-306 2 PoCs

COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.

CVE-2021-47720
orangescrum Database
8.7
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid to potentially extract or modify database information.

CVE-2021-47854
DD-WRT General
8.7
HIGH
EPSS
0.1%
2021 CWE-120 1 PoC

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.