3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-40149
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
62.9%
2021 1 PoC

The web server of the E1 Zoom camera through 3.0.0.716 discloses its SSL private key via the root web server directory. In this way an attacker can download the entire key via the /self.key URI.

CVE-2021-26333
PSP Driver General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-200 3 PoCs

An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages.

CVE-2021-31901
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.

CVE-2021-29281
Software Genérico General
N/A
UNKNOWN
EPSS
3.6%
2021 2 PoCs

File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.

CVE-2021-33581
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

MashZone NextGen through 10.7 GA has an SSRF vulnerability that allows an attacker to interact with arbitrary TCP services, by abusing the feature to check the availability of a PPM connection. This occurs in com.idsscheer.ppmmashup.web.webservice.impl.ZPrestoAdminWebService.

CVE-2021-46022
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.

CVE-2021-43471
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability.

CVE-2021-20079
Nessus General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.

CVE-2021-39696
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-185810717

CVE-2021-33403
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An integer overflow in the transfer function of a smart contract implementation for Lancer Token, an Ethereum ERC20 token, allows the owner to cause unexpected financial losses between two large accounts during a transaction.

CVE-2021-33322
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to change the user’s password via the old password reset token.

CVE-2021-42639
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.

CVE-2021-29063
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

CVE-2021-37419
Software Genérico General
N/A
UNKNOWN
EPSS
7.7%
2021 2 PoCs

Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.

CVE-2021-45469
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.

CVE-2021-37543
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.

CVE-2021-41551
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP file that contains a symbolic link.

CVE-2021-45419
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.

CVE-2021-31249
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2021 1 PoC

A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.

CVE-2021-28488
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).