94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47667
ZendTo Web
10.0
CRITICAL
EPSS
1.1%
2021 CWE-78 1 PoC

An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping off a file via a POST /dropoff request.

CVE-2021-33975
Software Genérico General
10.0
CRITICAL
EPSS
0.3%
2021 2 PoCs

Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges.

CVE-2021-40422
Swift Sensors Gateway General
10.0
CRITICAL
EPSS
11.0%
2021 CWE-798 1 PoC

An authentication bypass vulnerability exists in the device password generation functionality of Swift Sensors Gateway SG3-1010. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-41277
🔥 KEV metabase General ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-200 13 PoCs

Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (including environment variables). URLs were not validated prior to being loaded. This issue is fixed in a new maintenance release (0.40.5 and 1.40.5), and any subsequent release after that. If you’re unable to upgrade immediately, you can mitigate this by including rules in your reverse proxy or load balancer or WAF to provide a validation filter before the applicat

CVE-2021-40426
libsox Windows
10.0
CRITICAL
EPSS
0.5%
2021 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox 14.4.2 and master commit 42b3557e. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-33970
Software Genérico General
10.0
CRITICAL
EPSS
2.0%
2021 2 PoCs

Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate priveleges.

CVE-2021-40401
Gerbv General
10.0
CRITICAL
EPSS
0.4%
2021 CWE-252 1 PoC

A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-44228
🔥 KEV Apache Log4j2 Web Windows ⚡ nuclei
10.0
CRITICAL
EPSS
94.4%
2021 CWE-502 276 PoCs

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnera

CVE-2021-2244
Hyperion Analytic Provider Services Web Database
10.0
CRITICAL
EPSS
2.1%
2021 2 PoCs

Vulnerability in the Hyperion Analytic Provider Services product of Oracle Hyperion (component: JAPI) and Essbase Analytic Provider Services product of Oracle Essbase (component: JAPI). Supported versions that are affected are Hyperion Analytic Provider Services 11.1.2.4 and 12.2.1.4, and Essbase Analytic Provider Services 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Analytic Provider Services. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Hyperio

CVE-2021-40391
Gerbv General
10.0
CRITICAL
EPSS
0.5%
2021 CWE-390 1 PoC

An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-43936
WebHMI General
10.0
CRITICAL
EPSS
28.4%
2021 2 PoCs

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

CVE-2021-41269
cron-utils General
10.0
CRITICAL
EPSS
1.9%
2021 CWE-94 1 PoC

cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no kno

CVE-2021-40393
Gerbv General
10.0
CRITICAL
EPSS
0.4%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-4434
Social Sharing Plugin – Social Warfare Web Windows
10.0
CRITICAL
EPSS
8.0%
2021 CWE-94 1 PoC

The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.

CVE-2021-21951
Anker General
10.0
CRITICAL
EPSS
0.9%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.

CVE-2021-21961
Sealevel General
10.0
CRITICAL
EPSS
2.3%
2021 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-21322
fastify-http-proxy Web
10.0
CRITICAL
EPSS
0.2%
2021 CWE-20 1 PoC

fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user expect that accessing `/priv` on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.3.1.

CVE-2021-41163
discourse Cloud
10.0
CRITICAL
EPSS
3.7%
2021 CWE-74 2 PoCs

Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could lead to remote code execution. This resulted from a lack of validation in subscribe_url values. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. To workaround the issue without updating, requests with a path starting /webhooks/aws path could be blocked at an upstream proxy.

CVE-2021-21950
Anker General
10.0
CRITICAL
EPSS
0.9%
2021 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution.

CVE-2021-36206
CEVAS Database
10.0
CRITICAL
EPSS
0.6%
2021 CWE-79 1 PoC

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.