3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-0315
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-169763814.

CVE-2021-26804
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.

CVE-2021-20094
Wibu-Systems CodeMeter General
N/A
UNKNOWN
EPSS
6.8%
2021 1 PoC

A denial of service vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to crash the CodeMeter Runtime Server.

CVE-2021-27568
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 4 PoCs

An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.

CVE-2021-37425
Software Genérico General
N/A
UNKNOWN
EPSS
8.7%
2021 3 PoCs

Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.

CVE-2021-25949
set-getter General
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-20083
jquery-plugin-query-object General
N/A
UNKNOWN
EPSS
7.3%
2021 1 PoC

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object 2.2.3 allows a malicious user to inject properties into Object.prototype.

CVE-2021-36666
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission.

CVE-2021-33055
Software Genérico General
N/A
UNKNOWN
EPSS
21.8%
2021 1 PoC

Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.

CVE-2021-28153
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)

CVE-2021-43325
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.

CVE-2021-31907
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.

CVE-2021-43463
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

CVE-2021-26401
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

CVE-2021-34693
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

CVE-2021-20076
Tenable.sc General
N/A
UNKNOWN
EPSS
3.4%
2021 1 PoC

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.

CVE-2021-0507
Android General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181860042

CVE-2021-20156
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not appear to be any signature validation done to determine if it is from a known and trusted source. This includes firmware updates that are done via the automated "check for updates" in the admin interface. If an attacker is able to masquerade as the update server, the device will not verify that the firmware updates downloaded are legitimate.

CVE-2021-28149
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.7%
2021 0 PoCs

Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user input and allows a remote attacker with minimal privileges to download any file from the device by substituting ../ (e.g., ../../etc/passwd) This can be carried out with a web browser by changing the file name accordingly. Upon visiting log_download.cgi?type=../../etc/passwd and logging in, the web server will allow a download of the contents of the /etc/passwd file.

CVE-2021-3456
smart_proxy_salt General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-863 1 PoC

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.