7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47727
Selea Targa IP OCR-ANPR Camera General
8.7
HIGH
EPSS
0.2%
2021 CWE-306 2 PoCs

Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage.

CVE-2021-47959
WPGraphQL Web Database Windows
8.7
HIGH
EPSS
0.0%
2021 CWE-770 1 PoC

WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows unauthenticated attackers to exhaust server resources by sending batched GraphQL queries with duplicated fields. Attackers can send POST requests to the GraphQL endpoint with amplified field duplication payloads to trigger server out-of-memory conditions and MySQL connection errors.

CVE-2021-4463
BEMS API Web
8.7
HIGH
EPSS
0.2%
2021 CWE-552 2 PoCs

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

CVE-2021-47709
Smart Home Ruvie CCTV Bridge DVR Service General
8.7
HIGH
EPSS
0.1%
2021 CWE-306 2 PoCs

COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.

CVE-2021-47706
COMMAX Biometric Access Control System General
8.7
HIGH
EPSS
0.6%
2021 CWE-565 2 PoCs

COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.

CVE-2021-47719
COMMAX WebViewer ActiveX Control General
8.7
HIGH
EPSS
0.1%
2021 CWE-787 2 PoCs

COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit boundary errors in Commax_WebViewer.ocx to cause buffer overflow conditions and potentially gain code execution.

CVE-2021-47705
COMMAX UMS Client ActiveX Control General
8.7
HIGH
EPSS
0.1%
2021 CWE-787 2 PoCs

COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and potentially gain system-level access.

CVE-2021-47850
Mini Mouse Web
8.7
HIGH
EPSS
0.3%
2021 CWE-22 1 PoC

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path parameters.

CVE-2021-47726
NuCom 11N Wireless Router Web Networking
8.7
HIGH
EPSS
0.1%
2021 CWE-522 2 PoCs

NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode the admin password in Base64 format.

CVE-2021-47701
OpenBMCS Web
8.7
HIGH
EPSS
0.1%
2021 CWE-862 2 PoCs

OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.

CVE-2021-47718
OpenBMCS Web
8.7
HIGH
EPSS
0.3%
2021 CWE-548 2 PoCs

OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.

CVE-2021-47854
DD-WRT General
8.7
HIGH
EPSS
0.1%
2021 CWE-120 1 PoC

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.

CVE-2021-4466
IPCop General
8.7
HIGH
EPSS
0.4%
2021 CWE-78 1 PoC

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.

CVE-2021-47943
TextPattern CMS Web
8.7
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

TextPattern CMS 4.8.7 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by uploading malicious PHP files through the file upload functionality. Attackers can upload a PHP shell via the Files section in the content area and execute commands by accessing the uploaded file at /textpattern/files/ with GET parameters passed to the system function.

CVE-2021-47752
AWebServer GhostBuilding DevOps Web Database
8.7
HIGH
EPSS
0.3%
2021 CWE-770 1 PoC

AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.

CVE-2021-47888
Textpattern Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 1 PoC

Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.

CVE-2021-39946
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVE-2021-47794
ZesleCP General
8.7
HIGH
EPSS
0.2%
2021 CWE-78 2 PoCs

ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FTP accounts with shell injection payloads. Attackers can exploit the FTP account creation endpoint by injecting a reverse shell command that establishes a network connection to a specified listening host.

CVE-2021-47904
PhreeBooks Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 2 PoCs

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

CVE-2021-47755
Oliver Library Server General
8.7
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.