3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-27971
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.

CVE-2021-43039
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.

CVE-2021-39674
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442

CVE-2021-26311
SEV/SEV-ES General
N/A
UNKNOWN
EPSS
1.3%
2021 1 PoC

In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

CVE-2021-27205
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

CVE-2021-37922
Software Genérico General
N/A
UNKNOWN
EPSS
26.0%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files from one directory to another.

CVE-2021-40903
Software Genérico General
N/A
UNKNOWN
EPSS
11.6%
2021 3 PoCs

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

CVE-2021-29023
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

CVE-2021-20129
Draytek VigorConnect General
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.

CVE-2021-26388
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

CVE-2021-40857
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 3 PoCs

Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.

CVE-2021-0443
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-170474245

CVE-2021-44531
Node General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-295 2 PoCs

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.

CVE-2021-26271
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

CVE-2021-37158
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.

CVE-2021-29133
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.

CVE-2021-36705
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly to system.

CVE-2021-26914
Software Genérico General
N/A
UNKNOWN
EPSS
64.4%
2021 4 PoCs

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.

CVE-2021-33563
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.

CVE-2021-39425
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.