2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-23772
github.com/kataras/iris General
7.5
HIGH
EPSS
0.9%
2021 2 PoCs

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

CVE-2021-21005
FL SWITCH General
7.5
HIGH
EPSS
0.0%
2021 CWE-362 1 PoC

In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.

CVE-2021-4184
Wireshark General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-40142
Software Genérico General
7.5
HIGH
EPSS
0.5%
2021 2 PoCs

In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.

CVE-2021-43859
xstream General
7.5
HIGH
EPSS
1.9%
2021 CWE-400 2 PoCs

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. Se

CVE-2021-43444
Software Genérico General
7.5
HIGH
EPSS
1.5%
2021 1 PoC

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.

CVE-2021-31889
Capital Embedded AR Classic 431-422 Web
7.5
HIGH
EPSS
1.6%
2021 CWE-191 1 PoC

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and Denial-of-Service conditions. (FSMD-2021-0015)

CVE-2021-34561
WHA-GW-F2D2-0-AS- Z2-ETH Networking
7.5
HIGH
EPSS
0.3%
2021 CWE-350 1 PoC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

CVE-2021-43046
TIBCO PartnerExpress General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

The Interior Server and Gateway Server components of TIBCO Software Inc.'s TIBCO PartnerExpress contain an easily exploitable vulnerability that allows an unauthenticated attacker with network access to obtain session tokens for the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO PartnerExpress: versions 6.2.1 and below.

CVE-2021-3757
immerjs/immer General
7.5
HIGH
EPSS
0.6%
2021 CWE-1321 1 PoC

immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-36369
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2021 1 PoC

An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.

CVE-2021-29486
cumulative-distribution-function General
7.5
HIGH
EPSS
0.7%
2021 CWE-20 1 PoC

cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution function from data array of x values. In versions prior to 2.0.0 apps using this library on improper data may crash or go into an infinite-loop. In the case of a nodejs server-app using this library to act on invalid non-numeric data, the nodejs server may crash. This may affect other users of this server and/or require the server to be rebooted for proper operation. In the case of a browser app using this library to act on invalid non-numeric data, that browser may crash or

CVE-2021-27634
SAP NetWeaver AS for ABAP (RFC Gateway) General
7.5
HIGH
EPSS
0.2%
2021 CWE-787 2 PoCs

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method ThCpicDtCreate () causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-2419
Outside In Technology Web Database
7.5
HIGH
EPSS
1.0%
2021 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the

CVE-2021-42359
WP DSGVO Tools (GDPR) General ⚡ nuclei
7.5
HIGH
EPSS
20.1%
2021 CWE-284 0 PoCs

WP DSGVO Tools (GDPR) <= 3.1.23 had an AJAX action, ‘admin-dismiss-unsubscribe‘, which lacked a capability check and a nonce check and was available to unauthenticated users, and did not check the post type when deleting unsubscription requests. As such, it was possible for an attacker to permanently delete an arbitrary post or page on the site by sending an AJAX request with the “action” parameter set to “admin-dismiss-unsubscribe” and the “id” parameter set to the post to be deleted. Sending such a request would move the post to the trash, and repeating the request would permanently delete t

CVE-2021-26419
Internet Explorer 11 General
7.5
HIGH
EPSS
34.1%
2021 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2021-3828
nltk/nltk General
7.5
HIGH
EPSS
0.4%
2021 CWE-1333 1 PoC

nltk is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-32568
zmister2016/mrdoc General
7.5
HIGH
EPSS
0.3%
2021 CWE-502 1 PoC

mrdoc is vulnerable to Deserialization of Untrusted Data

CVE-2021-30201
Software Genérico Web Cloud
7.5
HIGH
EPSS
0.3%
2021 6 PoCs

The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fetched by the system and returned to the attacker. Detailed description Given the following request: ``` POST /vsaWS/KaseyaWS.asmx HTTP/1.1 Content-Type: text/xml;charset=UTF-8 Host: 192.168.1.194:18081 Content-Length: 406 <soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:kas="KaseyaWS"> <soapenv:Header/> <soapenv:Body> <kas:PrimitiveResetPassword> <!--type: string--> <kas:XmlRequest><![CDATA[<!DOCTYPE data SYSTEM "ht