3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-33793
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.

CVE-2021-26353
3rd Gen EPYC General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.

CVE-2021-3487
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-29662
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVE-2021-33208
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.

CVE-2021-33655
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 1 PoC

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-44033
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.

CVE-2021-41738
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2021 2 PoCs

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

CVE-2021-38714
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

CVE-2021-25162
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
35.9%
2021 3 PoCs

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2021-37388
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2021 1 PoC

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

CVE-2021-20067
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.

CVE-2021-3199
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2021 2 PoCs

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

CVE-2021-3375
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.

CVE-2021-40510
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

CVE-2021-28683
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

CVE-2021-25768
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.

CVE-2021-25172
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.