2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3689
yiisoft/yii2 General
8.1
HIGH
EPSS
0.4%
2021 CWE-1241 1 PoC

yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator

CVE-2021-2228
Incentive Compensation Web Database
8.1
HIGH
EPSS
1.2%
2021 1 PoC

Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Incentive Compensation. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Incentive Compensation accessible data as well as unauthorized access to critical data or complete access to all Oracle Incentive Compensa

CVE-2021-27876
🔥 KEV Software Genérico General
8.1
HIGH
EPSS
1.1%
2021 1 PoC

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privile

CVE-2021-2271
Work in Process Web Database
8.1
HIGH
EPSS
1.2%
2021 1 PoC

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Resource Exceptions). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CV

CVE-2021-4124
meetecho/janus-gateway Web
8.1
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-2237
General Ledger Web Database
8.1
HIGH
EPSS
1.2%
2021 1 PoC

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Account Hierarchy Manager). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.1 Ba

CVE-2021-2363
Public Sector Financials (International) Web Database
8.1
HIGH
EPSS
1.2%
2021 1 PoC

Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Financials (International) accessible data as well as unauthorized access to critical data or complet

CVE-2021-2406
Collaborative Planning Web Database
8.1
HIGH
EPSS
0.9%
2021 1 PoC

Vulnerability in the Oracle Collaborative Planning product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Collaborative Planning. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Collaborative Planning accessible data as well as unauthorized access to critical data or complete access to all Oracle Collaborative Planning accessi

CVE-2021-21389
BuddyPress Web Windows ⚡ nuclei
8.1
HIGH
EPSS
93.3%
2021 CWE-863 2 PoCs

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVE-2021-36205
Metasys General
8.1
HIGH
EPSS
0.3%
2021 CWE-459 1 PoC

Under certain circumstances the session token is not cleared on logout.

CVE-2021-2233
Enterprise Asset Management Web Database
8.1
HIGH
EPSS
1.2%
2021 1 PoC

Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Setup). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Asset Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Enter

CVE-2021-33705
SAP NetWeaver Enterprise Portal General
8.1
HIGH
EPSS
0.7%
2021 CWE-918 1 PoC

The SAP NetWeaver Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, component Iviews Editor contains a Server-Side Request Forgery (SSRF) vulnerability which allows an unauthenticated attacker to craft a malicious URL which when clicked by a user can make any type of request (e.g. POST, GET) to any internal or external server. This can result in the accessing or modification of data accessible from the Portal but will not affect its availability.

CVE-2021-34470
Microsoft Exchange Server 2013 Cumulative Update 23 Windows
8.0
HIGH
EPSS
4.7%
2021 2 PoCs

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2021-25962
shuup General
8.0
HIGH
EPSS
0.4%
2021 CWE-1236 1 PoC

“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.

CVE-2021-21300
git Windows
8.0
HIGH
EPSS
64.5%
2021 CWE-59 15 PoCs

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March

CVE-2021-21505
Dell EMC Integrated System for Microsoft Azure Stack Hub Cloud
8.0
HIGH
EPSS
5.4%
2021 CWE-255 2 PoCs

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.

CVE-2021-35485
Software Genérico General
8.0
HIGH
EPSS
0.1%
2021 1 PoC

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.

CVE-2021-35499
TIBCO Nimbus Web
8.0
HIGH
EPSS
0.4%
2021 1 PoC

The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.4.0 and below.

CVE-2021-35234
Orion Core Database
8.0
HIGH
EPSS
0.8%
2021 CWE-89 1 PoC

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

CVE-2021-29427
gradle General
8.0
HIGH
EPSS
0.6%
2021 CWE-829 1 PoC

In Gradle from version 5.1 and before version 7.0 there is a vulnerability which can lead to information disclosure and/or dependency poisoning. Repository content filtering is a security control Gradle introduced to help users specify what repositories are used to resolve specific dependencies. This feature was introduced in the wake of the "A Confusing Dependency" blog post. In some cases, Gradle may ignore content filters and search all repositories for dependencies. This only occurs when repository content filtering is used from within a `pluginManagement` block in a settings file. This ma