3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25804
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.

CVE-2021-38823
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.

CVE-2021-25424
Tizen wearable devices General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-287 1 PoC

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

CVE-2021-38569
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function calls during the handling of XFA forms or link objects.

CVE-2021-25829
Software Genérico General
N/A
UNKNOWN
EPSS
3.8%
2021 1 PoC

An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. Using this bug, an attacker is able to produce a denial of service attack that can eventually shut down the target server.

CVE-2021-28093
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.

CVE-2021-29657
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

arch/x86/kvm/svm/nested.c in the Linux kernel before 5.11.12 has a use-after-free in which an AMD KVM guest can bypass access control on host OS MSRs when there are nested guests, aka CID-a58d9166a756. This occurs because of a TOCTOU race condition associated with a VMCB12 double fetch in nested_svm_vmrun.

CVE-2021-35309
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

CVE-2021-34805
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 2 PoCs

An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

CVE-2021-29203
HPE Edgeline Infrastructure Management Software General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 0 PoCs

A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software, prior to version 1.22. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of arbitrary commands, gaining privileged access, causing denial of service, and changing the configuration. HPE has released a software update to resolve the vulnerability in the HPE Edgeline Infrastructure Manager.

CVE-2021-29921
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 6 PoCs

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVE-2021-20270
python-pygments General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-835 1 PoC

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

CVE-2021-31319
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-32923
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which caused them to be incorrectly treated as non-expiring during subsequent use. Fixed in 1.5.9, 1.6.5, and 1.7.2.

CVE-2021-28665
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can lead to excessive consumption of memory and CPU resources, and possibly a denial of service.

CVE-2021-41550
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 2 PoCs

Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.

CVE-2021-46416
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.

CVE-2021-40375
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.

CVE-2021-31229
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handling while parsing crafted XML files, which leads to an out-of-bounds write of a one byte constant.

CVE-2021-31932
Software Genérico General
N/A
UNKNOWN
EPSS
7.3%
2021 1 PoC

Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.