3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-43454
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService path. .

CVE-2021-43187
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.

CVE-2021-46421
Software Genérico General
N/A
UNKNOWN
EPSS
3.3%
2021 1 PoC

Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.

CVE-2021-34427
Eclipse BIRT General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.7%
2021 CWE-20 3 PoCs

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.

CVE-2021-20323
keycloak-services General ⚡ nuclei
N/A
UNKNOWN
EPSS
66.1%
2021 CWE-79 3 PoCs

A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.

CVE-2021-3189
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ substring.

CVE-2021-33504
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Couchbase Server before 7.1.0 has Incorrect Access Control.

CVE-2021-38571
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.

CVE-2021-0652
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185178568

CVE-2021-42635
Software Genérico General
N/A
UNKNOWN
EPSS
23.5%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

CVE-2021-46453
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2021 1 PoC

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.

CVE-2021-37322
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.

CVE-2021-43183
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

CVE-2021-29265
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and shared status, aka CID-9380afd6df70.

CVE-2021-31680
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml file.

CVE-2021-26408
1st Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.

CVE-2021-28429
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local attackers to cause a denial of service (DoS) via crafted .mov file.

CVE-2021-26233
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-46363
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

CVE-2021-31612
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on Zhuhai Jieli AC690X devices does not properly handle the reception of an oversized LMP packet greater than 17 bytes during the LMP auto rate procedure, allowing attackers in radio range to trigger a deadlock via a crafted LMP packet.