3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-1061
NVIDIA Virtual GPU Manager General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-20107
SLOAN General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

There exists an unauthenticated BLE Interface in Sloan SmartFaucets including Optima EAF, Optima ETF/EBF, BASYS EFX, and Flushometers including SOLIS. The vulnerability allows for unauthenticated kinetic effects and information disclosure on the faucets. It is possible to use the Bluetooth Low Energy (BLE) connectivity to read and write to many BLE characteristics on the device. Some of these control the flow of water, the sensitivity of the sensors, and information about maintenance.

CVE-2021-25443
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-825 1 PoC

A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an attacker.

CVE-2021-31321
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-43287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
79.2%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.

CVE-2021-31611
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order LMP Setup procedure that is followed by a malformed LMP packet, allowing attackers in radio range to deadlock a device via a crafted LMP packet. The user needs to manually reboot the device to restore communication.

CVE-2021-29006
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
20.6%
2021 2 PoCs

rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.

CVE-2021-0330
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In add_user_ce and remove_user_ce of storaged.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in storaged with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-170732441

CVE-2021-4044
OpenSSL General
N/A
UNKNOWN
EPSS
33.3%
2021 1 PoC

Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of memory). Such a negative return value is mishandled by OpenSSL and will cause an IO function (such as SSL_connect() or SSL_do_handshake()) to not indicate success and a subsequent call to SSL_get_error() to return the value SSL_ERROR_WANT_RETRY_VERIFY. This return value is only supposed to be returned by OpenSSL if the application has previously called SSL_CTX_set_cert_verify_cal

CVE-2021-36707
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.

CVE-2021-33617
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&userName= username enumeration, because the response (to a failed login request) is null only when the username is invalid.

CVE-2021-27971
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.

CVE-2021-43039
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

CVE-2021-39674
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442

CVE-2021-26311
SEV/SEV-ES General
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

CVE-2021-27205
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

CVE-2021-37922
Software Genérico General
N/A
UNKNOWN
EPSS
26.0%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

CVE-2021-40903
Software Genérico General
N/A
UNKNOWN
EPSS
11.6%
2021 3 PoCs

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

CVE-2021-29023
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.