3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25172
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.

CVE-2021-44444
JT Utilities General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-125 1 PoC

A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-15052)

CVE-2021-31552
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules related to blocking accounts after account creation. Such rules would allow for user accounts to be created while blocking only the IP address used to create an account (and not the user account itself). Such rules could also be used by a nefarious, unprivileged user to catalog and enumerate any number of IP addresses related to these account creations.

CVE-2021-41569
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.8%
2021 0 PoCs

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to the DS2CSF macro. Users can escape the context of the configured user-controllable variable and append additional functions native to the macro but not included as variables within the library. This includes a function that retrieves files from the host OS.

CVE-2021-28376
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.

CVE-2021-46703
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-25419
Samsung Internet General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-703 1 PoC

Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.

CVE-2021-30949
watchOS General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, tvOS 15.2, macOS Monterey 12.1, Security Update 2021-008 Catalina, iOS 15.2 and iPadOS 15.2, watchOS 8.3. A malicious application may be able to execute arbitrary code with kernel privileges.

CVE-2021-20718
mod_auth_openidc General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

CVE-2021-31786
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic Audio implementation on Actions ATS2815 and ATS2819 devices does not properly handle a connection attempt from a host with the same BDAddress as the current connected BT host, allowing attackers to trigger a disconnection and deadlock of the device by connecting with a forged BDAddress that matches the original connected host.

CVE-2021-32570
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.

CVE-2021-20074
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and execute arbitrary OS commands.

CVE-2021-41504
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authentication for the devices command interface may allow further attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-0430
Android General
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

In rw_mfc_handle_read_op of rw_mfc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution via a malicious NFC packet with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-178725766

CVE-2021-43185
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.

CVE-2021-45911
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow in the main function. It allows an attacker to write 2 bytes outside the boundaries of the buffer.

CVE-2021-43286
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.

CVE-2021-26332
3rd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

CVE-2021-26260
OpenEXR General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-400 1 PoC

An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.

CVE-2021-42973
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.