3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-37165
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2021 1 PoC

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.

CVE-2021-20157
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

It is possible for an unauthenticated, malicious user to force the device to reboot due to a hidden administrative command.

CVE-2021-26384
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.

CVE-2021-37166
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

A buffer overflow issue leading to denial of service was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When HMI3 starts up, it binds a local service to a TCP port on all interfaces of the device, and takes extensive time for the GUI to connect to the TCP socket, allowing the connection to be hijacked by an external attacker.

CVE-2021-41821
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

CVE-2021-3520
lz4 General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-190 3 PoCs

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CVE-2021-34543
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

CVE-2021-32563
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 2 PoCs

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVE-2021-44692
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

BuddyBoss Platform through 1.8.0 allows remote attackers to obtain the email address of each user. When creating a new user, it generates a Unique ID for their profile. This UID is their private email address with symbols removed and periods replaced with hyphens. For example. JohnDoe@example.com would become /members/johndoeexample-com and Jo.test@example.com would become /members/jo-testexample-com. The members list is available to everyone and (in a default configuration) often without authentication. It is therefore trivial to collect a list of email addresses.

CVE-2021-32458
Trend Micro Home Network Security General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.

CVE-2021-0708
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In runDumpHeap of ActivityManagerShellCommand.java, there is a possible deletion of system files due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-183262161

CVE-2021-25947
nestie General
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-26906
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0; 17.x through 17.9.1; and 18.x through 18.2.0, and Certified Asterisk through 16.8-cert5. An SDP negotiation vulnerability in PJSIP allows a remote server to potentially crash Asterisk by sending specific SIP responses that cause an SDP negotiation failure.

CVE-2021-33327
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.

CVE-2021-26574
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.

CVE-2021-39409
Software Genérico General
N/A
UNKNOWN
EPSS
16.9%
2021 1 PoC

A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be authenticated.

CVE-2021-29395
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

CVE-2021-46368
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

CVE-2021-45078
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

CVE-2021-43193
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.