4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-27651
Pega Infinity General ⚡ nuclei
9.8
CRITICAL
EPSS
92.2%
2021 CWE-287 5 PoCs

In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.

CVE-2021-4436
3DPrint Lite Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
76.9%
2021 1 PoC

The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in its p3dlite_handle_upload AJAX action , allowing unauthenticated users to upload arbitrary file to the web server. However, there is a .htaccess, preventing the file to be accessed on Web servers such as Apache.

CVE-2021-21914
ImageGear General
9.8
CRITICAL
EPSS
1.2%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-30117
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.0%
2021 1 PoC

The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the parameter fldrId. Detailed description --- Given the following request: ``` GET /InstallTab/exportFldr.asp?fldrId=1’ HTTP/1.1 Host: 192.168.1.194 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:85.0) Gecko/20100101 Firefox/85.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate DNT: 1 Connection: close Upgrade-Insecure-Requests: 1 Cookie: ASPSESSIONIDCQACCQCA=MHBOFJHBCIP

CVE-2021-20021
🔥 KEV Email Security Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
91.2%
2021 CWE-269 1 PoC

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

CVE-2021-4039
NWA1100-NH firmware General
9.8
CRITICAL
EPSS
62.8%
2021 CWE-78 1 PoC

A command injection vulnerability in the web interface of the Zyxel NWA-1100-NH firmware could allow an attacker to execute arbitrary OS commands on the device.

CVE-2021-26102
FortiWAN General
9.8
CRITICAL
EPSS
60.8%
2021 CWE-305 1 PoC

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker to delete files on the system by sending a crafted POST request. In particular, deleting specific configuration files will reset the Admin password to its default value.

CVE-2021-23376
ffmpegdotjs General
9.8
CRITICAL
EPSS
0.6%
2021 1 PoC

This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-28481
Microsoft Exchange Server 2019 Cumulative Update 9 Windows ⚡ nuclei
9.8
CRITICAL
EPSS
34.4%
2021 0 PoCs

Microsoft Exchange Server Remote Code Execution Vulnerability

CVE-2021-25941
deep-override General
9.8
CRITICAL
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-36888
Image Hover Effects Ultimate (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
68.3%
2021 CWE-284 0 PoCs

Unauthenticated Arbitrary Options Update vulnerability leading to full website compromise discovered in Image Hover Effects Ultimate (versions <= 9.6.1) WordPress plugin.

CVE-2021-21944
ImageGear General
9.8
CRITICAL
EPSS
0.4%
2021 CWE-122 1 PoC

Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger these vulnerabilities.This heap-based buffer oveflow takes place trying to copy the first 12 bits from local variable.

CVE-2021-4073
RegistrationMagic Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.0%
2021 CWE-287 0 PoCs

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

CVE-2021-35395
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2021 1 PoC

Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer overflow in formWsc due to unsafe copy of submit-url parameter - stack buffer overflow in formWlanMultip

CVE-2021-21784
Accusoft General
9.8
CRITICAL
EPSS
0.3%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the JPG format SOF marker processing of Accusoft ImageGear 19.8. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-4226
RSFirewall! Web Networking
9.8
CRITICAL
EPSS
0.1%
2021 1 PoC

RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.

CVE-2021-40417
Blackmagic Design General
9.8
CRITICAL
EPSS
1.5%
2021 CWE-680 1 PoC

When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer. Due to an integer overflow with regards to this calculation, this can result in an undersized heap buffer being allocated. When this heap buffer is written to, a heap-based buffer overflow will occur. This can result in code execution under the context of the application.

CVE-2021-21795
Accusoft General
9.8
CRITICAL
EPSS
0.5%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 19.9. A specially crafted malformed file can lead to an integer overflow that, in turn, leads to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-3918
kriszyp/json-schema General
9.8
CRITICAL
EPSS
1.3%
2021 CWE-1321 1 PoC

json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-35394
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
94.2%
2021 1 PoC

Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.