3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-26574
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.

CVE-2021-43536
Thunderbird General
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-40091
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

CVE-2021-42556
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.

CVE-2021-29395
Software Genérico General
N/A
UNKNOWN
EPSS
1.2%
2021 2 PoCs

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

CVE-2021-33793
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write because the Cross-Reference table is mishandled during Office document conversion.

CVE-2021-33491
Software Genérico General
N/A
UNKNOWN
EPSS
4.4%
2021 2 PoCs

OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandling of relative paths in mail addresses in conjunction with auto-configuration DNS records.

CVE-2021-25417
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-285 1 PoC

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

CVE-2021-46441
Software Genérico General
N/A
UNKNOWN
EPSS
18.3%
2021 1 PoC

In the "webupg" binary of D-Link DIR-825 G1, because of the lack of parameter verification, attackers can use "cmd" parameters to execute arbitrary system commands after obtaining authorization.

CVE-2021-37546
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

CVE-2021-22884
Node General
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-350 3 PoCs

Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is resolved via DNS, i.e., over network. If the attacker controls the victim's DNS server or can spoof its responses, the DNS rebinding protection can be bypassed by using the “localhost6” domain. As long as the attacker uses the “localhost6” domain, they can still apply the attack described in CVE-2018-7160.

CVE-2021-31324
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

CVE-2021-40379
Software Genérico General
N/A
UNKNOWN
EPSS
40.1%
2021 1 PoC

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.

CVE-2021-29957
Thunderbird General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.

CVE-2021-39706
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-200164168

CVE-2021-46778
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.

CVE-2021-43189
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

CVE-2021-36232
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

CVE-2021-40597
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

CVE-2021-38207
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.