3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-43540
Firefox General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been uninstalled with the extension. This vulnerability affects Firefox < 95.

CVE-2021-32100
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A remote file inclusion vulnerability exists in Artica Pandora FMS 742, exploitable by the lowest privileged user.

CVE-2021-29022
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.

CVE-2021-34414
Zoom on-premise Meeting Connector Controller, Zoom on-premise Meeting Connector MMR, Zoom on-premise Recording Connector, Zoom on-premise Virtual Room Connector, Zoom on-premise Virtual Room Connector Load Balancer General
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.20201217, Zoom on-premise Meeting Connector MMR before version 4.6.348.20201217, Zoom on-premise Recording Connector before version 3.8.42.20200905, Zoom on-premise Virtual Room Connector before version 4.4.6620.20201110, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network proxy configuration, which could lead to remote command injection on the on-premise image by a web portal ad

CVE-2021-46354
Software Genérico General
N/A
UNKNOWN
EPSS
39.2%
2021 1 PoC

Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vulnerability in the parameter "Addr" in cmd site. The ability to send requests to other systems can allow the vulnerable server to filtrate the real IP of the web server or increase the attack surface.

CVE-2021-24000
Firefox General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they were on a separate tab. In conjunction with certain elements (such as &lt;input type="file"&gt;) this could have led to an attack where a user was confused about the origin of the webpage and potentially disclosed information they did not intend to. This vulnerability affects Firefox < 88.

CVE-2021-33571
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses. (validate_ipv4_address and validate_ipv46_address are unaffected with Python 3.9.5+..) .

CVE-2021-30809
iOS and iPadOS General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2021-0688
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In lockNow of PhoneWindowManager.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-161149543

CVE-2021-39271
Software Genérico General
N/A
UNKNOWN
EPSS
4.0%
2021 2 PoCs

OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attacker-supplied Python code in the class attribute of a .bscw file. This is fixed in 5.0.12, 5.1.10, 5.2.4, 7.3.3, and 7.4.3.

CVE-2021-37925
Software Genérico General
N/A
UNKNOWN
EPSS
20.5%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.

CVE-2021-3152
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
45.2%
2021 0 PoCs

Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks against custom integrations. NOTE: the vendor's perspective is that the vulnerability itself is in custom integrations written by third parties, not in Home Assistant; however, Home Assistant does have a security update that is worthwhile in addressing this situation

CVE-2021-37928
Software Genérico General
N/A
UNKNOWN
EPSS
37.4%
2021 1 PoC

Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execution.

CVE-2021-46418
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
63.1%
2021 1 PoC

An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.

CVE-2021-28680
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

The devise_masquerade gem before 1.3 allows certain attacks when a password's salt is unknown. An application that uses this gem to let administrators masquerade/impersonate users loses one layer of security protection compared to a situation where Devise (without this extension) is used. If the server-side secret_key_base value became publicly known (for instance if it is committed to a public repository by mistake), there are still other protections in place that prevent an attacker from impersonating any user on the site. When masquerading is not used in a plain Devise application, one must

CVE-2021-0434
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In onReceive of BluetoothPermissionRequest.java, there is a possible phishing attack allowing a malicious Bluetooth device to acquire permissions based on insufficient information presented to the user in the consent dialog. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9Android ID: A-167403112

CVE-2021-31785
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on Actions ATS2815 and ATS2819 chipsets does not properly handle the reception of multiple LMP_host_connection_req packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device via crafted LMP packets. Manual user intervention is required to restart the device and restore Bluetooth communication.

CVE-2021-43199
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.

CVE-2021-31829
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive information previously operated on by the kernel.

CVE-2021-43293
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via Server Side Request Forgery (SSRF).