94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-21873
Lantronix Web
9.1
CRITICAL
EPSS
1.0%
2021 CWE-78 1 PoC

A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-29508
Wire Web
9.1
CRITICAL
EPSS
0.5%
2021 CWE-502 1 PoC

Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019. This also applies to the fork of Wire.

CVE-2021-33701
DMIS Mobile Plug-In Database
9.1
CRITICAL
EPSS
1.2%
2021 CWE-89 4 PoCs

DMIS Mobile Plug-In or SAP S/4HANA, versions - DMIS 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 710, 2011_1_731, 710, 2011_1_752, 2020, SAPSCORE 125, S4CORE 102, 102, 103, 104, 105, allows an attacker with access to highly privileged account to execute manipulated query in NDZT tool to gain access to Superuser account, leading to SQL Injection vulnerability, that highly impacts systems Confidentiality, Integrity and Availability.

CVE-2021-40412
Software Genérico Web
9.1
CRITICAL
EPSS
8.7%
2021 CWE-78 1 PoC

An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [8] the devname variable, that has the value of the name parameter provided through the SetDevName API, is not validated properly. This would lead to an OS command injection.

CVE-2021-45650
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R7000 before 1.0.11.110, R7900 before 1.0.4.30, R8000 before 1.0.4.62, RS400 before 1.5.1.80, R6400v2 before 1.0.4.102, R7000P before 1.3.2.126, R6700v3 before 1.0.4.102, and R6900P before 1.3.2.126.

CVE-2021-34566
750-81xx/xxx-xxxFW General
9.1
CRITICAL
EPSS
0.9%
2021 CWE-120 1 PoC

In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.

CVE-2021-28506
EOS Web
9.1
CRITICAL
EPSS
0.5%
2021 CWE-285 1 PoC

An issue has recently been discovered in Arista EOS where certain gNOI APIs incorrectly skip authorization and authentication which could potentially allow a factory reset of the device.

CVE-2021-40410
Software Genérico Web
9.1
CRITICAL
EPSS
8.7%
2021 CWE-78 1 PoC

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_data->dns1 variable, that has the value of the dns1 parameter provided through the SetLocal API, is not validated properly. This would lead to an OS command injection.

CVE-2021-46753
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
9.1
CRITICAL
EPSS
0.2%
2021 1 PoC

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity.

CVE-2021-21874
Lantronix Web
9.1
CRITICAL
EPSS
1.0%
2021 CWE-78 1 PoC

A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-2253
Advanced Supply Chain Planning Web Database
9.1
CRITICAL
EPSS
1.7%
2021 1 PoC

Vulnerability in the Oracle Advanced Supply Chain Planning product of Oracle Supply Chain (component: Core). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Supply Chain Planning. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Supply Chain Planning accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Supply Cha

CVE-2021-21001
Series PFC200 Controller General
9.1
CRITICAL
EPSS
0.2%
2021 CWE-22 1 PoC

On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.

CVE-2021-45496
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2021 1 PoC

NETGEAR D7000 devices before 1.0.1.82 are affected by authentication bypass.

CVE-2021-21819
D-Link General
9.1
CRITICAL
EPSS
1.3%
2021 CWE-78 1 PoC

A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-21887
Lantronix Web
9.1
CRITICAL
EPSS
3.6%
2021 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-21895
Lantronix Web
9.1
CRITICAL
EPSS
2.8%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-40411
Software Genérico Web
9.1
CRITICAL
EPSS
1.3%
2021 CWE-78 1 PoC

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_data->dns2 variable, that has the value of the dns2 parameter provided through the SetLocalLink API, is not validated properly. This would lead to an OS command injection.

CVE-2021-41097
path Web Networking ⚡ nuclei
9.1
CRITICAL
EPSS
11.7%
2021 CWE-1321 1 PoC

aurelia-path is part of the Aurelia platform and contains utilities for path manipulation. There is a prototype pollution vulnerability in aurelia-path before version 1.1.7. The vulnerability exposes Aurelia application that uses `aurelia-path` package to parse a string. The majority of this will be Aurelia applications that employ the `aurelia-router` package. An example is this could allow an attacker to change the prototype of base object class `Object` by tricking an application to parse the following URL: `https://aurelia.io/blog/?__proto__[asdf]=asdf`. The problem is patched in version `

CVE-2021-4457
ZoomSounds Web
9.1
CRITICAL
EPSS
0.4%
2021 1 PoC

The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an arbitrary file anywhere on the web server.