3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-28960
Software Genérico General
N/A
UNKNOWN
EPSS
6.7%
2021 1 PoC

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

CVE-2021-38199
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.

CVE-2021-31251
Software Genérico General
N/A
UNKNOWN
EPSS
10.8%
2021 1 PoC

An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Technology Inc allows obtaining a privileged connection with the target device by supplying a specially malformed request and an attacker may force the remote telnet server to believe that the user has already authenticated.

CVE-2021-47541
Linux General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net/mlx4_en: Fix an use-after-free bug in mlx4_en_try_alloc_resources() In mlx4_en_try_alloc_resources(), mlx4_en_copy_priv() is called and tmp->tx_cq will be freed on the error path of mlx4_en_copy_priv(). After that mlx4_en_alloc_resources() is called and there is a dereference of &tmp->tx_cq[t][i] in mlx4_en_alloc_resources(), which could lead to a use after free problem on failure of mlx4_en_copy_priv(). Fix this bug by adding a check of mlx4_en_copy_priv() This bug was found by a static analyzer. The analysis employs

CVE-2021-0600
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In onCreate of DeviceAdminAdd.java, there is a possible way to mislead a user to activate a device admin app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-179042963

CVE-2021-37927
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.

CVE-2021-43056
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.

CVE-2021-26718
Kaspersky Internet Security for Mac General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

CVE-2021-37420
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

CVE-2021-42637
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use user-controlled input to craft a URL, resulting in a Server Side Request Forgery (SSRF) vulnerability.

CVE-2021-3640
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-362 3 PoCs

A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable faulting memory page. A privileged local user could use this flaw to crash the system or escalate their privileges on the system.

CVE-2021-20034
SMA100 General
N/A
UNKNOWN
EPSS
5.8%
2021 CWE-284 1 PoC

An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.

CVE-2021-4115
polkitd General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-400 3 PoCs

There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned

CVE-2021-26363
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.

CVE-2021-40378
Software Genérico General
N/A
UNKNOWN
EPSS
40.6%
2021 1 PoC

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.

CVE-2021-43541
Thunderbird General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-31532
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (silicon rev 0A) include an undocumented ROM patch peripheral that allows unsigned, non-persistent modification of the internal ROM.

CVE-2021-43503
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-36209
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.

CVE-2021-41716
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Maharashtra State Electricity Board Mahavitara Android Application 8.20 and prior is vulnerable to remote account takeover due to OTP fixation vulnerability in password rest function