7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-44394
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44414
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. DelUser param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-23352
madge General
8.6
HIGH
EPSS
0.6%
2021 1 PoC

This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath option parameter which when the .image(), .svg() or .dot() functions are called, is executed by the childprocess.exec function.

CVE-2021-44404
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetZoomFocus param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-47746
NodeBB Plugin Emoji Web
8.6
HIGH
EPSS
0.1%
2021 CWE-73 1 PoC

NodeBB Plugin Emoji 3.2.1 contains an arbitrary file write vulnerability that allows administrative users to write files to arbitrary system locations through the emoji upload API. Attackers with admin access can craft file upload requests with directory traversal to overwrite system files by manipulating the file path parameter.

CVE-2021-21965
Sealevel General
8.6
HIGH
EPSS
0.4%
2021 CWE-284 1 PoC

A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2021-44398
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=stop param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44354
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-44417
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. GetAlarm param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-22195
gitlab-vscode-extension DevOps
8.6
HIGH
EPSS
0.2%
2021 1 PoC

Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system

CVE-2021-44366
RLC-410W Web
8.6
HIGH
EPSS
0.3%
2021 CWE-20 1 PoC

Multiple denial of service vulnerabilities exist in the cgiserver.cgi JSON command parser functionality of Reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-36288
VNX2 General
8.6
HIGH
EPSS
0.9%
2021 CWE-22 1 PoC

Dell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/write restricted files

CVE-2021-44408
Software Genérico Web
8.6
HIGH
EPSS
0.2%
2021 CWE-20 1 PoC

A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. TestFtp param is not object. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-39153
xstream General
8.5
HIGH
EPSS
0.6%
2021 CWE-434 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVE-2021-47799
Visual Tools DVR VX16 General
8.5
HIGH
EPSS
0.0%
2021 CWE-266 1 PoC

Visual Tools DVR VX16 version 4.2.28 contains a local privilege escalation vulnerability in its Sudo configuration that allows attackers to gain root access. Attackers can exploit the unsafe Sudo settings by using mount commands to bind a shell, enabling unauthorized system-level privileges.

CVE-2021-39146
xstream General ⚡ nuclei
8.5
HIGH
EPSS
47.2%
2021 CWE-434 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVE-2021-39150
xstream Web
8.5
HIGH
EPSS
2.1%
2021 CWE-502 4 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least ve

CVE-2021-47861
Event Log Explorer General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Event Log Explorer 4.9.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations that will be executed with LocalSystem account privileges during service startup.

CVE-2021-30480
Software Genérico Windows
8.5
HIGH
EPSS
9.1%
2021 3 PoCs

Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.

CVE-2021-47898
Epson USB Display General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in intermediate directories to gain elevated system access.