3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-31609
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation in Silicon Labs iWRAP 6.3.0 and earlier does not properly handle the reception of an oversized LMP packet greater than 17 bytes, allowing attackers in radio range to trigger a crash in WT32i via a crafted LMP packet.

CVE-2021-3610
ImageMagick General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-125 1 PoC

A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

CVE-2021-22057
VMware Workspace ONE Access General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

CVE-2021-0390
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. This could lead to local escalation of privilege by a background user on the same device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174749461

CVE-2021-31698
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shell metacharacters in quectel_handle_fumo_cfg input in atfwd_daemon.

CVE-2021-34543
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

The web administration server in Solar-Log 500 before 2.8.2 Build 52 does not require authentication, which allows remote attackers to gain administrative privileges by connecting to the server. As a result, the attacker can modify configuration files and change the system status. Fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

CVE-2021-32563
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 2 PoCs

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVE-2021-35450
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

A Server Side Template Injection in the Entando Admin Console 6.3.9 and before allows a user with privileges to execute FreeMarker template with command execution via freemarker.template.utility.Execute

CVE-2021-31684
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.

CVE-2021-31220
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

SES Evolution before 2.1.0 allows modifying security policies by leveraging access of a user having read-only access to security policies.

CVE-2021-38160
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior

CVE-2021-41554
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functionality in these affected endpoints: /archibus/schema/ab-edit-users.axvw, /archibus/schema/ab-data-dictionary-table.axvw, /archibus/schema/ab-schema-add-field.axvw, /archibus/schema/ab-core/views/process-navigator/ab-my-user-profile.axvw. By not verifying the permissions for access to resources, it allows a potential attacker to view pages that are not allowed. Specifically, it was found that any authenticated user can reach the administrative console for user management by di

CVE-2021-43536
Thunderbird General
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-40091
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

CVE-2021-42556
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.

CVE-2021-33491
Software Genérico General
N/A
UNKNOWN
EPSS
4.4%
2021 2 PoCs

OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

CVE-2021-25417
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-285 1 PoC

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

CVE-2021-46441
Software Genérico General
N/A
UNKNOWN
EPSS
18.3%
2021 1 PoC

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

CVE-2021-37546
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

CVE-2021-31324
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.