3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-40597
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.

CVE-2021-38207
Software Genérico General
N/A
UNKNOWN
EPSS
2.5%
2021 1 PoC

drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.

CVE-2021-20316
samba General
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-362 1 PoC

A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permissions to read or modify share metadata, to perform this operation outside of the share.

CVE-2021-0520
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In several functions of MemoryFileSystem.cpp and related files, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-176237595

CVE-2021-35312
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Service.exe" has incorrect permissions, allowing a local unprivileged user to replace it with a malicious file that will be executed with "LocalSystem" privileges.

CVE-2021-43637
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-45491
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

3CX System through 2022-03-17 stores cleartext passwords in a database.

CVE-2021-31323
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-24157
Orbit Fox by ThemeIsle General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

Orbit Fox by ThemeIsle has a feature to add custom scripts to the header and footer of a page or post. There were no checks to verify that a user had the unfiltered_html capability prior to saving the script tags, thus allowing lower-level users to inject scripts that could potentially be malicious.

CVE-2021-25946
nconf-toml General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-23410
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-31910
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.3, information disclosure via SSRF was possible.

CVE-2021-35206
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Gitpod before 0.6.0 allows unvalidated redirects.

CVE-2021-0589
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In BTM_TryAllocateSCN of btm_scn.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-180939982

CVE-2021-40149
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
62.9%
2021 1 PoC

The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.

CVE-2021-26333
PSP Driver General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-200 3 PoCs

An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages.

CVE-2021-31901
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.

CVE-2021-29281
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2021 2 PoCs

File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.

CVE-2021-33581
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.

CVE-2021-46022
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.