7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-2039
Siebel Core - Server Framework Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Siebel Core - Server Framework product of Oracle Siebel CRM (component: Search). Supported versions that are affected are 20.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Core - Server Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Core - Server Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or com

CVE-2021-2181
Document Management and Collaboration Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Attachments). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration. While the vulnerability is in Oracle Document Management and Collaboration, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Ora

CVE-2021-29460
kirby Web
7.6
HIGH
EPSS
1.1%
2021 CWE-79 1 PoC

Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful content like `<script>` tags. The direct link to that file can be sent to other users or visitors of the site. If the victim opens that link in a browser where they are logged in to Kirby, the script will run and can for example trigger requests to Kirby's API with the permissions of the victim. This vulnerability is critical if you might have potential attackers in your group of authenticated Panel users, as they can escalate their privileges if they get access to the Panel

CVE-2021-2049
BI Publisher (formerly XML Publisher) Web Database
7.6
HIGH
EPSS
0.6%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Administration). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized a

CVE-2021-3915
bookstackapp/bookstack General
7.6
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-33601
F-Secure Internet Gatekeeper General
7.6
HIGH
EPSS
0.7%
2021 1 PoC

A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

CVE-2021-31950
Microsoft SharePoint Enterprise Server 2016 Windows
7.6
HIGH
EPSS
1.7%
2021 1 PoC

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2021-28828
TIBCO Administrator - Enterprise Edition Database
7.6
HIGH
EPSS
0.4%
2021 1 PoC

The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, and TIBCO Administrator - Enterprise Edition for z/Linux contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a SQL injection attack on the affected system. Affected releases are TIBCO

CVE-2021-45524
Software Genérico General
7.6
HIGH
EPSS
0.2%
2021 1 PoC

NETGEAR R8000 devices before 1.0.4.62 are affected by a buffer overflow by an authenticated user.

CVE-2021-45493
Software Genérico General
7.6
HIGH
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

CVE-2021-38616
Software Genérico General
7.6
HIGH
EPSS
0.9%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.

CVE-2021-3666
fiznool/body-parser-xml General
7.6
HIGH
EPSS
0.4%
2021 CWE-1321 1 PoC

body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-2013
BI Publisher (formerly XML Publisher) Web Database
7.6
HIGH
EPSS
0.7%
2021 1 PoC

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unautho

CVE-2021-32808
ckeditor4 Web
7.6
HIGH
EPSS
1.4%
2021 CWE-79 2 PoCs

ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version >= 4.13.0. The problem has been recognized and patched. The fix will be available in version 4.16.2.

CVE-2021-2458
Identity Manager Web Database
7.6
HIGH
EPSS
0.5%
2021 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Identity Console). Supported versions that are affected are 11.1.2.2.0, 11.1.2.3.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Identity Manager, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical da

CVE-2021-23435
clearance Web
7.6
HIGH
EPSS
0.3%
2021 1 PoC

This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value of session[:return_to]. If the value used for return_to contains multiple leading slashes (/////example.com) the user ends up being redirected to the external domain that comes after the slashes (http://example.com).

CVE-2021-4164
janeczku/calibre-web Web
7.6
HIGH
EPSS
0.1%
2021 CWE-352 1 PoC

calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-23702
object-extend General
7.6
HIGH
EPSS
0.4%
2021 1 PoC

The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.

CVE-2021-45595
Software Genérico General
7.6
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, RBS10 before 2.7.3.22, RBS20 before 2.7.3.22, RBS40 before 2.7.3.22, RBS50 before 2.7.3.22, RBK12 before 2.7.3.22, RBK20 before 2.7.3.22, RBK40 before 2.7.3.22, and RBK50 before 2.7.3.22.

CVE-2021-23404
sqlite-web Web Database
7.6
HIGH
EPSS
0.1%
2021 1 PoC

This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.