94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2019-25686
Core FTP General
8.7
HIGH
EPSS
0.2%
2019 CWE-306 1 PoC

Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.

CVE-2019-25249
dLAN 550 duo+ Starter Kit General
8.7
HIGH
EPSS
0.2%
2019 CWE-266 2 PoCs

devolo dLAN 500 AV Wireless+ 3.1.0-1 contains an authentication bypass vulnerability that allows attackers to enable hidden services through the htmlmgr CGI script. Attackers can enable telnet and remote shell services, reboot the device, and gain root access without a password by manipulating system configuration parameters.

CVE-2019-25630
PhreeBooks ERP Web
8.7
HIGH
EPSS
0.8%
2019 CWE-434 1 PoC

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

CVE-2019-25673
Laravel File Manager Web
8.7
HIGH
EPSS
0.1%
2019 CWE-434 1 PoC

UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by accessing the uploaded file through the working directory path.

CVE-2019-25579
phpTransformer Web
8.7
HIGH
EPSS
3.1%
2019 CWE-22 1 PoC

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.

CVE-2019-25472
Telefone IP TIP 200 General
8.7
HIGH
EPSS
0.0%
2019 CWE-73 1 PoC

IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files including /etc/shadow and configuration files without proper authorization.

CVE-2021-47888
Textpattern Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 1 PoC

Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.

CVE-2021-47701
OpenBMCS Web
8.7
HIGH
EPSS
0.1%
2021 CWE-862 2 PoCs

OpenBMCS 2.4 allows an attacker to escalate privileges from a read user to an admin user by manipulating permissions and exploiting a vulnerability in the update_user_permissions.php script. Attackers can submit a malicious HTTP POST request to PHP scripts in '/plugins/useradmin/' directory.

CVE-2021-47719
COMMAX WebViewer ActiveX Control General
8.7
HIGH
EPSS
0.1%
2021 CWE-787 2 PoCs

COMMAX WebViewer ActiveX Control 2.1.4.5 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit boundary errors in Commax_WebViewer.ocx to cause buffer overflow conditions and potentially gain code execution.

CVE-2021-47713
Hasura GraphQL DevOps
8.7
HIGH
EPSS
0.2%
2021 CWE-770 1 PoC

Hasura GraphQL 1.3.3 contains a denial of service vulnerability that allows attackers to overwhelm the service by crafting malicious GraphQL queries with excessive nested fields. Attackers can send repeated requests with extremely long query strings and multiple threads to consume server resources and potentially crash the GraphQL endpoint.

CVE-2021-47849
Mini Mouse Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.

CVE-2021-4463
BEMS API Web
8.7
HIGH
EPSS
0.2%
2021 CWE-552 2 PoCs

Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulnerability in the 'downloads' endpoint. The 'fileName' parameter is not properly sanitized, allowing attackers to craft traversal sequences and access sensitive files outside the intended directory.

CVE-2021-4466
IPCop General
8.7
HIGH
EPSS
0.4%
2021 CWE-78 1 PoC

IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-based administration interface. The email configuration component inserts user-controlled values, including the EMAIL_PW parameter, directly into system-level operations without proper input sanitation. By modifying the email password field to include shell metacharacters and issuing a save-and-test-mail action, an authenticated attacker can execute arbitrary operating system commands with the privileges of the web interface, resulting in full system compromise.

CVE-2021-47755
Oliver Library Server General
8.7
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.

CVE-2021-47705
COMMAX UMS Client ActiveX Control General
8.7
HIGH
EPSS
0.1%
2021 CWE-787 2 PoCs

COMMAX UMS Client ActiveX Control 1.7.0.2 contains a heap-based buffer overflow vulnerability that allows attackers to execute arbitrary code by providing excessively long string arrays through multiple functions. Attackers can exploit improper boundary validation in CNC_Ctrl.dll to cause heap corruption and potentially gain system-level access.

CVE-2021-47741
ZBL EPON ONU Broadband Router Networking
8.7
HIGH
EPSS
0.1%
2021 CWE-522 2 PoCs

ZBL EPON ONU Broadband Router V100R001 contains a privilege escalation vulnerability that allows limited administrative users to elevate access by sending requests to configuration endpoints. Attackers can exploit the vulnerability by accessing the configuration backup or password page to disclose the super user password and gain additional privileged functionalities.

CVE-2021-47904
PhreeBooks Web
8.7
HIGH
EPSS
0.5%
2021 CWE-434 2 PoCs

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

CVE-2021-47704
OpenBMCS Web Database
8.7
HIGH
EPSS
0.0%
2021 CWE-89 2 PoCs

OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.

CVE-2021-47721
orangescrum General
8.7
HIGH
EPSS
0.0%
2021 CWE-639 1 PoC

Orangescrum 1.8.0 contains a privilege escalation vulnerability that allows authenticated users to take over other project-assigned accounts by manipulating session cookies. Attackers can extract the victim's unique ID from the page source and replace their own session cookie to gain unauthorized access to another user's account.

CVE-2021-47795
GeoVision Geowebserver Web
8.7
HIGH
EPSS
0.0%
2021 CWE-22 1 PoC

GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.