7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-47882
FreeLAN Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

FreeLAN 2.2 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service startup.

CVE-2021-39139
xstream General
8.5
HIGH
EPSS
0.7%
2021 CWE-502 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. A user is only affected if using the version out of the box with JDK 1.7u21 or below. However, this scenario can be adjusted easily to an external Xalan that works regardless of the version of the Java runtime. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types.

CVE-2021-47845
Spy Emergency Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system startup or service restart.

CVE-2021-47859
ActivIdentity General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

ActivIdentity 8.2 contains an unquoted service path vulnerability in the ac.sharedstore service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in C:\Program Files\Common Files\ActivIdentity\ to inject malicious executables and escalate privileges.

CVE-2021-47878
eBeam Education Suite General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

eBeam Education Suite 2.5.0.9 contains an unquoted service path vulnerability in the eBeam Device Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem privileges during service startup.

CVE-2021-47730
Selea Targa IP OCR-ANPR Camera Web
8.5
HIGH
EPSS
0.1%
2021 CWE-352 2 PoCs

Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a logged-in user visits the page.

CVE-2021-30480
Software Genérico Windows
8.5
HIGH
EPSS
9.1%
2021 3 PoCs

Zoom Chat through 2021-04-09 on Windows and macOS allows certain remote authenticated attackers to execute arbitrary code without user interaction. An attacker must be within the same organization, or an external party who has been accepted as a contact. NOTE: this is specific to the Zoom Chat software, which is different from the chat feature of the Zoom Meetings and Zoom Video Webinars software.

CVE-2021-47889
LAN Messenger General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Softros LAN Messenger 9.6.4 contains an unquoted service path vulnerability in the SoftrosSpellChecker service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Softros Systems\Softros Messenger\Spell Checker\' to inject malicious executables and escalate privileges.

CVE-2021-35651
Hyperion Essbase Administration Services Web Database
8.5
HIGH
EPSS
0.4%
2021 1 PoC

Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Essbase Administration Services ac

CVE-2021-47804
Wise Care General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Wise Care 365 5.6.7.568 contains an unquoted service path vulnerability in the WiseBootAssistant service running with LocalSystem privileges. Attackers can exploit this by inserting a malicious executable in the service path, which will execute with elevated system privileges when the service restarts.

CVE-2021-39152
xstream Web ⚡ nuclei
8.5
HIGH
EPSS
61.8%
2021 CWE-502 4 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least ve

CVE-2021-47805
Disk Savvy Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to inject malicious executables that will be run with elevated LocalSystem privileges.

CVE-2021-47803
iFunbox General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts.

CVE-2021-47787
TotalAV General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

TotalAV 5.15.69 contains an unquoted service path vulnerability in multiple system services running with LocalSystem privileges. Attackers can place malicious executables in specific unquoted path segments to potentially gain SYSTEM-level access by exploiting the service path configuration.

CVE-2021-47898
Epson USB Display General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Epson USB Display 1.6.0.0 contains an unquoted service path vulnerability in the EMP_UDSA service running with LocalSystem privileges. Attackers can exploit the unquoted path by placing malicious executables in intermediate directories to gain elevated system access.

CVE-2021-39153
xstream General
8.5
HIGH
EPSS
0.6%
2021 CWE-434 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream, if using the version out of the box with Java runtime version 14 to 8 or with JavaFX installed. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVE-2021-47780
Macro Expert General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Macro Expert 4.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the improperly configured service path to inject malicious executables that will be run with LocalSystem permissions during service startup.

CVE-2021-47860
Custom JS Plugin Web
8.5
HIGH
EPSS
0.1%
2021 CWE-352 2 PoCs

GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to execute remote code on the hosting server when an authenticated administrator visits the page.

CVE-2021-47974
VX Search General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

VX Search 13.5.28 contains an unquoted service path vulnerability in both VX Search Server and VX Search Enterprise services that allows local attackers to escalate privileges. Attackers can place malicious executables in unquoted path directories like C:\Program Files\VX Search to execute arbitrary code with LocalSystem privileges when services restart.

CVE-2021-39154
xstream General
8.5
HIGH
EPSS
0.7%
2021 CWE-434 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.