94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47865
ProFTPD DevOps
8.7
HIGH
EPSS
0.0%
2021 CWE-770 1 PoC

ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access.

CVE-2021-47711
Xperience Database
8.7
HIGH
EPSS
0.1%
2021 CWE-89 1 PoC

A SQL injection vulnerability in Kentico Xperience allows authenticated editors to inject malicious SQL queries via online marketing macro method parameters. This enables unauthorized database access and potential data manipulation by exploiting macro method input validation weaknesses.

CVE-2021-47794
ZesleCP General
8.7
HIGH
EPSS
0.2%
2021 CWE-78 2 PoCs

ZesleCP 3.1.9 contains an authenticated remote code execution vulnerability that allows attackers to create malicious FTP accounts with shell injection payloads. Attackers can exploit the FTP account creation endpoint by injecting a reverse shell command that establishes a network connection to a specified listening host.

CVE-2021-47710
Smart Home Ruvie CCTV Bridge DVR Service General
8.7
HIGH
EPSS
0.2%
2021 CWE-306 2 PoCs

COMMAX Smart Home System is a smart IoT home solution that allows an unauthenticated attacker to disclose RTSP credentials in plain-text by exploiting the /overview.asp endpoint. Attackers can access sensitive information, including login credentials and DVR settings, by submitting a GET request to this endpoint.

CVE-2021-47720
orangescrum Database
8.7
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Orangescrum 1.8.0 contains an authenticated SQL injection vulnerability that allows authorized users to manipulate database queries through multiple vulnerable parameters. Attackers can inject malicious SQL code into parameters like old_project_id, project_id, uuid, and uniqid to potentially extract or modify database information.

CVE-2021-47854
DD-WRT General
8.7
HIGH
EPSS
0.1%
2021 CWE-120 1 PoC

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.

CVE-2021-39946
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

CVE-2021-47850
Mini Mouse Web
8.7
HIGH
EPSS
0.3%
2021 CWE-22 1 PoC

Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path parameters.

CVE-2021-47706
COMMAX Biometric Access Control System General
8.7
HIGH
EPSS
0.6%
2021 CWE-565 2 PoCs

COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent physical controls in smart homes and buildings by exploiting cookie poisoning. Attackers can forge cookies to bypass authentication and disclose sensitive information.

CVE-2021-47709
Smart Home Ruvie CCTV Bridge DVR Service General
8.7
HIGH
EPSS
0.1%
2021 CWE-306 2 PoCs

COMMAX Smart Home System allows an unauthenticated attacker to change configuration and cause denial-of-service through the setconf endpoint. Attackers can trigger a denial-of-service scenario by sending a malformed request to the setconf endpoint.

CVE-2021-47727
Selea Targa IP OCR-ANPR Camera General
8.7
HIGH
EPSS
0.2%
2021 CWE-306 2 PoCs

Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage.

CVE-2021-4465
ReQuest Serious Play Pro Web
8.7
HIGH
EPSS
0.6%
2021 CWE-400 2 PoCs

ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption of service availability.

CVE-2021-47749
YouPHPTube Web
8.7
HIGH
EPSS
0.2%
2021 CWE-22 1 PoC

YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.

CVE-2021-47726
NuCom 11N Wireless Router Web Networking
8.7
HIGH
EPSS
0.1%
2021 CWE-522 2 PoCs

NuCom 11N Wireless Router 5.07.90 contains a privilege escalation vulnerability that allows non-privileged users to access administrative credentials through the configuration backup endpoint. Attackers can send a crafted HTTP GET request to the backup configuration page with a specific cookie to retrieve and decode the admin password in Base64 format.

CVE-2021-47788
WebsiteBaker General
8.7
HIGH
EPSS
0.1%
2021 CWE-434 1 PoC

WebsiteBaker 2.13.0 contains an authenticated remote code execution vulnerability that allows users with language editing permissions to execute arbitrary code. Attackers can exploit the language installation endpoint by manipulating language installation parameters to achieve remote code execution on the server.

CVE-2021-4469
SHO-110 Web
8.7
HIGH
EPSS
0.3%
2021 CWE-306 1 PoC

Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint without authentication. While the primary web interface on port 80 enforces authentication, the backdoor service allows any remote attacker to retrieve image snapshots by directly requesting the 'snapshot' endpoint. An attacker can repeatedly collect snapshots and reconstruct the camera stream, compromising the confidentiality of the monitored environment.

CVE-2021-47758
Chikitsa Patient Management System Web
8.7
HIGH
EPSS
0.7%
2021 CWE-434 1 PoC

Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitrary command execution on the server through a weaponized PHP script.

CVE-2021-22241
GitLab DevOps Web
8.7
HIGH
EPSS
0.2%
2021 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

CVE-2021-47752
AWebServer GhostBuilding DevOps Web Database
8.7
HIGH
EPSS
0.3%
2021 CWE-770 1 PoC

AWebServer GhostBuilding 18 contains a denial of service vulnerability that allows remote attackers to overwhelm the server by sending multiple concurrent HTTP requests. Attackers can generate high-volume requests to multiple endpoints including /mysqladmin to potentially crash or render the service unresponsive.

CVE-2021-47718
OpenBMCS Web
8.7
HIGH
EPSS
0.3%
2021 CWE-548 2 PoCs

OpenBMCS 2.4 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive files by exploiting directory listing functionality. Attackers can browse directories like /debug/ and /php/ to discover configuration files, database credentials, and system information.