3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-27918
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.

CVE-2021-25158
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
4.9%
2021 1 PoC

A remote arbitrary file read vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2021-37188
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firmware (because the bootloader does not verify that it is authentic), changing the behavior of the gateway.

CVE-2021-21974
VMware ESXi General
N/A
UNKNOWN
EPSS
57.9%
2021 6 PoCs

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

CVE-2021-39674
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442

CVE-2021-30006
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

CVE-2021-41829
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2021 1 PoC

Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain encryption key.

CVE-2021-40500
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) General
N/A
UNKNOWN
EPSS
1.2%
2021 CWE-611 1 PoC

SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML validations at endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation can enable the attacker to retrieve arbitrary files from the server.

CVE-2021-0331
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible overlay attack due to an insecure default value. This could lead to local escalation of privilege and notification access with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-170731783

CVE-2021-3516
libxml2 General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-416 2 PoCs

There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidentiality, integrity, and availability.

CVE-2021-29023
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mechanism that is predictable.

CVE-2021-43044
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The SNMP daemon was configured with a weak default community.

CVE-2021-3179
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authentication bypass.

CVE-2021-25169
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so websetservicecfg function.

CVE-2021-43188
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.

CVE-2021-26390
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.

CVE-2021-33325
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix pack 19, and 7.2 before fix pack 7, user's clear text passwords are stored in the database if workflow is enabled for user creation, which allows attackers with access to the database to obtain a user's password.

CVE-2021-45486
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash table is very small.

CVE-2021-43572
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.

CVE-2021-39623
Android General
N/A
UNKNOWN
EPSS
2.5%
2021 2 PoCs

In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194105348