17307 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-37415
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.0%
2021 1 PoC

Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.

CVE-2021-34569
750-81xx/xxx-xxxFW General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-787 1 PoC

In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to crash the diagnostic tool and write memory.

CVE-2021-23390
total4 General
9.8
CRITICAL
EPSS
1.3%
2021 1 PoC

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

CVE-2021-23389
total.js General
9.8
CRITICAL
EPSS
5.3%
2021 1 PoC

The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

CVE-2021-26379
2nd Gen AMD EPYC™ General
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

CVE-2021-45467
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
88.1%
2021 1 PoC

In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, an unauthenticated attacker can use %00 bytes to cause /user/loader.php to register an arbitrary API key, as demonstrated by a /user/loader.php?api=1&scripts= .%00./.%00./api/account_new_create&acc=guadaapi URI. Any number of %00 instances can be used, e.g., .%00%00%00./.%00%00%00./api/account_new_create could also be used for the scripts parameter.

CVE-2021-2108
WebLogic Server Database
9.8
CRITICAL
EPSS
27.8%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core Components). The supported version that is affected is 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2021-27664
exacqVision Web Service General
9.8
CRITICAL
EPSS
0.3%
2021 CWE-269 1 PoC

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

CVE-2021-3836
dbeaver/dbeaver General
9.8
CRITICAL
EPSS
0.2%
2021 CWE-611 1 PoC

dbeaver is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2021-22005
🔥 KEV VMware vCenter Server, VMware Cloud Foundation Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2021 16 PoCs

The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specially crafted file.

CVE-2021-30118
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
58.6%
2021 1 PoC

An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Management (RMM) 9.5.4.2149 and subsequently use these files to execute asp commands The api /SystemTab/uploader.aspx is vulnerable to an unauthenticated arbitrary file upload leading to RCE. An attacker can upload files with the privilege of the Web Server process and subsequently use these files to execute asp commands. Detailed description --- Given the following request: ``` POST /SystemTab/uploader.aspx?Filename=shellz.aspx&PathData=C%3A%5CKaseya%5CWebPages%5C&__RequestVali

CVE-2021-23274
TIBCO API Exchange Gateway Web Windows
9.8
CRITICAL
EPSS
0.2%
2021 1 PoC

The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric contains a vulnerability that theoretically allows an unauthenticated attacker with network access to execute a clickjacking attack on the affected system. A successful attack using this vulnerability does not require human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO API Exchange Gateway: versions 2.3.3 and below and TIBCO API Exchange Gateway Distribution for TIBCO Silver Fabric: versions 2.3.3

CVE-2021-23594
realms-shim General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.

CVE-2021-2075
WebLogic Server Database
9.8
CRITICAL
EPSS
26.8%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Samples). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2021-22502
🔥 KEV Operation Bridge Reporter. General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2021 1 PoC

Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.

CVE-2021-20028
🔥 KEV SonicWall SRA/SMA100 Networking Database
9.8
CRITICAL
EPSS
82.9%
2021 CWE-89 1 PoC

Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier

CVE-2021-35048
Fidelis Network Database
9.8
CRITICAL
EPSS
0.8%
2021 CWE-89 1 PoC

Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interface. The vulnerability could lead to exposure of authentication tokens in some versions of Fidelis software. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

CVE-2021-21776
Accusoft General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-131 1 PoC

An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-25943
101 General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-45382
🔥 KEV Software Genérico Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2021 0 PoCs

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.