3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-26718
Kaspersky Internet Security for Mac General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus protection.

CVE-2021-33327
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Portlet Configuration module in Liferay Portal 7.2.0 through 7.3.3, and Liferay DXP 7.0 fix pack pack 93 and 94, 7.1 fix pack 18, and 7.2 before fix pack 8, does not properly check user permission, which allows remote authenticated users to view the Guest and User role even if "Role Visibility" is enabled.

CVE-2021-26574
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.

CVE-2021-39409
Software Genérico General
N/A
UNKNOWN
EPSS
16.9%
2021 1 PoC

A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without needing to be authenticated.

CVE-2021-29395
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

CVE-2021-46368
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes with elevated privileges.

CVE-2021-45078
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.

CVE-2021-37420
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 2 PoCs

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.

CVE-2021-43193
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.

CVE-2021-33793
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.

CVE-2021-26353
3rd Gen EPYC General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.

CVE-2021-3487
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-29662
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVE-2021-33208
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.

CVE-2021-33655
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 1 PoC

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-44033
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.

CVE-2021-41738
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2021 2 PoCs

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

CVE-2021-38714
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

CVE-2021-25162
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
35.9%
2021 3 PoCs

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.