3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-27231
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Hestia Control Panel 1.3.5 and below, in a shared-hosting environment, sometimes allows remote authenticated users to create a subdomain for a different customer's domain name, leading to spoofing of services or email messages.

CVE-2021-45428
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

TLR-2005KSH is affected by an incorrect access control vulnerability. THe PUT method is enabled so an attacker can upload arbitrary files including HTML and CGI formats.

CVE-2021-25420
Galaxy Watch PlugIn General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-779 1 PoC

Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

CVE-2021-26331
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.

CVE-2021-29393
Software Genérico General
N/A
UNKNOWN
EPSS
14.2%
2021 2 PoCs

Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.

CVE-2021-32012
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

CVE-2021-3339
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

CVE-2021-37166
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.

CVE-2021-30048
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter.

CVE-2021-30072
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.

CVE-2021-34248
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Sin descripción disponible.

CVE-2021-31341
Mendix Database Replication Module General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-209 1 PoC

Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions prior to v7.0.1).

CVE-2021-31530
Software Genérico General
N/A
UNKNOWN
EPSS
4.5%
2021 1 PoC

Zoho ManageEngine ServiceDesk Plus MSP before 10522 is vulnerable to Information Disclosure.

CVE-2021-38199
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

CVE-2021-31251
Software Genérico General
N/A
UNKNOWN
EPSS
10.8%
2021 1 PoC

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

CVE-2021-47541
Linux General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net/mlx4_en: Fix an use-after-free bug in mlx4_en_try_alloc_resources() In mlx4_en_try_alloc_resources(), mlx4_en_copy_priv() is called and tmp->tx_cq will be freed on the error path of mlx4_en_copy_priv(). After that mlx4_en_alloc_resources() is called and there is a dereference of &tmp->tx_cq[t][i] in mlx4_en_alloc_resources(), which could lead to a use after free problem on failure of mlx4_en_copy_priv(). Fix this bug by adding a check of mlx4_en_copy_priv() This bug was found by a static analyzer. The analysis employs

CVE-2021-0600
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-179042963

CVE-2021-37927
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

CVE-2021-43056
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.

CVE-2021-26718
Kaspersky Internet Security for Mac General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.