3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-40857
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 3 PoCs

Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.

CVE-2021-0443
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In several functions of ScreenshotHelper.java and related files, there is a possible incorrectly saved screenshot due to a race condition. This could lead to local information disclosure across user profiles with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-170474245

CVE-2021-38564
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It allows an out-of-bounds read via util.scand.

CVE-2021-26274
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

The Agent in NinjaRMM 5.0.909 has Insecure Permissions.

CVE-2021-44531
Node General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-295 2 PoCs

Accepting arbitrary Subject Alternative Name (SAN) types, unless a PKI is specifically defined to use a particular SAN type, can result in bypassing name-constrained intermediates. Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 was accepting URI SAN types, which PKIs are often not defined to use. Additionally, when a protocol allows URI SANs, Node.js did not match the URI correctly.Versions of Node.js with the fix for this disable the URI SAN type when checking a certificate against a hostname. This behavior can be reverted through the --security-revert command-line option.

CVE-2021-26271
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

CVE-2021-37158
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS commands by starting a Counter-Strike server and using the map field to enter a Bash command.

CVE-2021-29133
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to read the contents of any file on the filesystem.

CVE-2021-36705
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter value of TR069 contains a trivial command injection where the value of the TR069_local_port parameter is passed directly to system.

CVE-2021-26914
Software Genérico General
N/A
UNKNOWN
EPSS
64.4%
2021 4 PoCs

NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.

CVE-2021-33563
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had a valid username. This might make brute-force attacks easier.

CVE-2021-39425
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

CVE-2021-31885
APOGEE MBC (PPC) (BACnet) General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-805 1 PoC

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V

CVE-2021-31872
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems may result in a buffer overflow or other security impact.

CVE-2021-41592
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.

CVE-2021-32558
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Asterisk before 16.8-cert10. If the IAX2 channel driver receives a packet that contains an unsupported media format, a crash can occur.

CVE-2021-38568
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows memory corruption during conversion of a PDF document to a different document format.

CVE-2021-30357
SSL Network Extender Client for Linux General
N/A
UNKNOWN
EPSS
30.0%
2021 CWE-209 1 PoC

SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

CVE-2021-33839
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.

CVE-2021-3378
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2021 2 PoCs

FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.