3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-36773
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).

CVE-2021-41738
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2021 2 PoCs

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

CVE-2021-38714
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

CVE-2021-25162
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
35.9%
2021 3 PoCs

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2021-42391
clickhouse General
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-369 1 PoC

Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0.

CVE-2021-37388
Software Genérico General
N/A
UNKNOWN
EPSS
3.4%
2021 1 PoC

A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an attacker to crash the webserver and might even gain remote code execution.

CVE-2021-20067
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.

CVE-2021-3199
Software Genérico General
N/A
UNKNOWN
EPSS
6.8%
2021 2 PoCs

Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.

CVE-2021-43201
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.

CVE-2021-3375
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.

CVE-2021-40510
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

CVE-2021-28683
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in TLS when an unknown TLS alert code is received.

CVE-2021-25768
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.

CVE-2021-25172
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.

CVE-2021-31552
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create an account (and not the user account itself). Such rules could also be used by a nefarious, unprivileged user to catalog and enumerate any number of IP addresses related to these account creations.

CVE-2021-41569
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.8%
2021 0 PoCs

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to the DS2CSF macro. Users can escape the context of the configured user-controllable variable and append additional functions native to the macro but not included as variables within the library. This includes a function that retrieves files from the host OS.

CVE-2021-28376
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

CVE-2021-25419
Samsung Internet General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-703 1 PoC

Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.

CVE-2021-30949
watchOS General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.