7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47734
CMSimple Web
8.6
HIGH
EPSS
0.1%
2021 CWE-98 1 PoC

CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.

CVE-2021-47747
meterN Web
8.6
HIGH
EPSS
0.4%
2021 CWE-78 2 PoCs

meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php scripts. Attackers can exploit the 'COMMANDx' and 'LIVECOMMANDx' POST parameters to execute arbitrary system commands with administrative privileges.

CVE-2021-29442
nacos Database ⚡ nuclei
8.6
HIGH
EPSS
92.8%
2021 CWE-306 1 PoC

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, the ConfigOpsController lets the user perform management operations like querying the database or even wiping it out. While the /data/remove endpoint is properly protected with the @Secured annotation, the /derby endpoint is not protected and can be openly accessed by unauthenticated users. These endpoints are only valid when using embedded storage (derby DB) so this issue should not affect those installations using external storage (e.g. mysql)

CVE-2021-44412
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetRec param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44385
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetPtzSerial param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44397
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=start param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47745
200 General
8.6
HIGH
EPSS
0.3%
2021 CWE-78 2 PoCs

Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' parameter in the ctm-config-upgrade.sh script to inject and execute arbitrary commands with root privileges.

CVE-2021-44411
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. Search param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44395
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetMask param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44383
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetAutoUpgrade param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-2069
Outside In Technology Web Database
8.6
HIGH
EPSS
1.1%
2021 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). Supported versions that are affected are 8.5.4 and 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Outside In Technology accessible data as well as unauthorized read access to a subset of Oracle Outside In Technology accessible data and unauth

CVE-2021-44394
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44355
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44378
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetEnc param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47918
Simple CMS Web Database
8.6
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.

CVE-2021-44363
Software Genérico Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. SetPush param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-3837
openwhyd/openwhyd General
8.6
HIGH
EPSS
0.1%
2021 CWE-285 1 PoC

openwhyd is vulnerable to Improper Authorization

CVE-2021-44408
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44403
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetPtzTattern param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47903
LiteSpeed Web Server Enterprise General
8.6
HIGH
EPSS
0.3%
2021 CWE-78 1 PoC

LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.