2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-2181
Document Management and Collaboration Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. While the vulnerability is in Oracle Document Management and Collaboration, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Ora

CVE-2021-23404
sqlite-web Web Database
7.6
HIGH
EPSS
0.1%
2021 1 PoC

This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.

CVE-2021-2013
BI Publisher (formerly XML Publisher) Web Database
7.6
HIGH
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unautho

CVE-2021-29460
kirby Web
7.6
HIGH
EPSS
1.1%
2021 CWE-79 1 PoC

Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim opens that link in a browser where they are logged in to Kirby, the script will run and can for example trigger requests to Kirby's API with the permissions of the victim. This vulnerability is critical if you might have potential attackers in your group of authenticated Panel users, as they can escalate their privileges if they get access to the Panel

CVE-2021-2049
BI Publisher (formerly XML Publisher) Web Database
7.6
HIGH
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Administration). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized a

CVE-2021-33699
SAP Fiori Client Native Mobile for Android General
7.6
HIGH
EPSS
2.2%
2021 1 PoC

Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive information.

CVE-2021-38616
Software Genérico General
7.6
HIGH
EPSS
0.9%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.

CVE-2021-31950
Microsoft SharePoint Enterprise Server 2016 Windows
7.6
HIGH
EPSS
1.7%
2021 1 PoC

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2021-3915
bookstackapp/bookstack General
7.6
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-2039
Siebel Core - Server Framework Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Search). Supported versions that are affected are 20.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Core - Server Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or com

CVE-2021-3555
Indoor 2K Indoor Camera General
7.6
HIGH
EPSS
0.3%
2021 CWE-120 1 PoC

A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions.

CVE-2021-39201
wordpress-develop Web Database Windows
7.6
HIGH
EPSS
0.5%
2021 CWE-79 3 PoCs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permission to post `unfiltered_html`. ### Patches This has been patched in WordPress 5.8, and will be pushed to older versions via minor releases (automatic updates). It's strongly recommended that you keep auto-updates enabled to receive the fix. ### References https://wordpress.org/

CVE-2021-45493
Software Genérico General
7.6
HIGH
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

CVE-2021-45524
Software Genérico General
7.6
HIGH
EPSS
0.2%
2021 1 PoC

NETGEAR R8000 devices before 1.0.4.62 are affected by a buffer overflow by an authenticated user.

CVE-2021-3780
chocobozzz/peertube Web
7.6
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

peertube is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-32808
ckeditor4 Web
7.6
HIGH
EPSS
1.4%
2021 CWE-79 2 PoCs

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

CVE-2021-2458
Identity Manager Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 11.1.2.2.0, 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical da

CVE-2021-23435
clearance Web
7.6
HIGH
EPSS
0.3%
2021 1 PoC

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

CVE-2021-4164
janeczku/calibre-web Web
7.6
HIGH
EPSS
0.1%
2021 CWE-352 1 PoC

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-23702
object-extend General
7.6
HIGH
EPSS
0.4%
2021 1 PoC

The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.