3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-33622
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value.

CVE-2021-39614
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 2 PoCs

D-Link DVX-2000MS contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values.

CVE-2021-46365
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

CVE-2021-0472
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In shouldLockKeyguard of LockTaskController.java, there is a possible way to exit App Pinning without a PIN due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-9 Android-10Android ID: A-176801033

CVE-2021-43339
Software Genérico General
N/A
UNKNOWN
EPSS
12.7%
2021 2 PoCs

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.

CVE-2021-26274
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

CVE-2021-39289
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVE-2021-26323
3rd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.

CVE-2021-20155
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 makes use of hardcoded credentials. It is possible to backup and restore device configurations via the management web interface. These devices are encrypted using a hardcoded password of "12345678".

CVE-2021-40380
Software Genérico General
N/A
UNKNOWN
EPSS
39.5%
2021 1 PoC

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.

CVE-2021-44686
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.

CVE-2021-26336
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.

CVE-2021-23955
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.

CVE-2021-3291
Software Genérico General
N/A
UNKNOWN
EPSS
32.6%
2021 2 PoCs

Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.

CVE-2021-25433
Tizen wearable devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-285 1 PoC

Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications to perform factory reset using dbus signal.

CVE-2021-27549
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen

CVE-2021-44648
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVE-2021-26235
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfc9, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-34144
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the reception of truncated LMP_SCO_Link_Request packets while no other BT connections are active, allowing attackers in radio range to prevent new BT connections (disabling the AB5301A inquiry and page scan procedures) via a crafted LMP packet. The user needs to manually perform a power cycle (restart) of the device to restore BT connectivity.

CVE-2021-44497
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to be miscalculated, which leads to a use after free condition a pointer is pushed into previously free memory by the loop.