7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-2349
Hyperion Essbase Administration Services Web Database
8.6
HIGH
EPSS
1.7%
2021 1 PoC

Vulnerability in the Hyperion Essbase Administration Services product of Oracle Essbase (component: EAS Console). Supported versions that are affected are 11.1.2.4 and 21.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Hyperion Essbase Administration Services. While the vulnerability is in Hyperion Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Hyperion Essbase Administration

CVE-2021-23442
@cookiex/deep General
8.6
HIGH
EPSS
0.5%
2021 1 PoC

This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.

CVE-2021-44359
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetCrop param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44377
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetImage param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47736
CMSimple_XH Web
8.6
HIGH
EPSS
1.1%
2021 CWE-94 1 PoC

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.

CVE-2021-44374
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-21382
restund DevOps Web
8.6
HIGH
EPSS
0.5%
2021 CWE-668 2 PoCs

Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopback address range. This allows you to reach any other service running on localhost which you might consider private. In the configuration that we ship (https://github.com/wireapp/ansible-restund/blob/master/templates/restund.conf.j2#L40-L43) the `status` interface of restund is enabled and is listening on `127.0.0.1`.The `status` interface allows users to issue administrative commands to `restund` like listing open relays or draining connections. It would be possible for an att

CVE-2021-21965
Sealevel General
8.6
HIGH
EPSS
0.4%
2021 CWE-284 1 PoC

A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-44391
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetEnc param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44355
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-21278
RSSHub Networking
8.6
HIGH
EPSS
0.5%
2021 CWE-74 1 PoC

RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues The fix in version 7f1c430 is to temporarily remove the problematic route and added a `no-new-func` rule to eslint.

CVE-2021-2067
Outside In Technology Web Database
8.6
HIGH
EPSS
1.1%
2021 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that are affected are 8.5.4 and 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauth

CVE-2021-44372
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetLocalLink param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44367
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetUpnp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44406
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetAutoFocus param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44369
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetNtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-21307
Lucee Web ⚡ nuclei
8.6
HIGH
EPSS
92.1%
2021 CWE-862 1 PoC

Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. In Lucee Admin before versions 5.3.7.47, 5.3.6.68 or 5.3.5.96 there is an unauthenticated remote code exploit. This is fixed in versions 5.3.7.47, 5.3.6.68 or 5.3.5.96. As a workaround, one can block access to the Lucee Administrator.

CVE-2021-44363
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetPush param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-3869
stanfordnlp/corenlp General
8.6
HIGH
EPSS
0.3%
2021 CWE-611 1 PoC

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

CVE-2021-44390
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Format param is not object. An attacker can send an HTTP request to trigger this vulnerability.