3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-28170
Jakarta Expression Language Implementation General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-20 1 PoC

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

CVE-2021-23999
Firefox ESR General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

CVE-2021-46010
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Totolink A3100R V5.9c.4577 suffers from Use of Insufficiently Random Values via the web configuration. The SESSION_ID is predictable. An attacker can hijack a valid session and conduct further malicious operations.

CVE-2021-27384
SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) General
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-788 1 PoC

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F

CVE-2021-33792
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trailer dictionary.

CVE-2021-20163
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 leaks information via the ftp web page. Usernames and passwords for all ftp users are revealed in plaintext on the ftpserver.asp page.

CVE-2021-25170
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetremoteimageinfo function.

CVE-2021-28293
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Password feature. The lack of correct configuration leads to recovery of the password reset link generated via the password reset functionality, and thus an unauthenticated attacker can set an arbitrary password for any user.

CVE-2021-36799
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local users to read project information. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-25282
Software Genérico General
N/A
UNKNOWN
EPSS
91.3%
2021 1 PoC

An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal.

CVE-2021-0475
Android General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

In on_l2cap_data_ind of btif_sock_l2cap.cc, there is possible memory corruption due to a use after free. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-175686168

CVE-2021-31252
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it.

CVE-2021-40491
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.

CVE-2021-26234
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation at 0x00402d8a, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-43454
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

CVE-2021-43187
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.

CVE-2021-46421
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2021 1 PoC

Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

CVE-2021-34427
Eclipse BIRT General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.7%
2021 CWE-20 3 PoCs

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

CVE-2021-20323
keycloak-services General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2021 CWE-79 3 PoCs

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

CVE-2021-3189
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.