3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-37546
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.

CVE-2021-31324
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

CVE-2021-33807
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
84.3%
2021 0 PoCs

Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.

CVE-2021-43532
Firefox General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affect

CVE-2021-40379
Software Genérico General
N/A
UNKNOWN
EPSS
40.1%
2021 1 PoC

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.

CVE-2021-29957
Thunderbird General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indicate that only parts of the message are protected. This vulnerability affects Thunderbird < 78.10.2.

CVE-2021-39706
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-200164168

CVE-2021-46778
AMD Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.

CVE-2021-43189
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.

CVE-2021-36232
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate privileges.

CVE-2021-40597
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

CVE-2021-38207
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.

CVE-2021-20316
samba General
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-362 1 PoC

A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.

CVE-2021-0520
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595

CVE-2021-35312
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

CVE-2021-43637
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-45491
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

3CX System through 2022-03-17 stores cleartext passwords in a database.

CVE-2021-31323
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-24157
Orbit Fox by ThemeIsle General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.

CVE-2021-25946
nconf-toml General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.