3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-37421
Software Genérico General
N/A
UNKNOWN
EPSS
8.9%
2021 1 PoC

Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.

CVE-2021-3345
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2021 3 PoCs

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

CVE-2021-36394
Moodle General
N/A
UNKNOWN
EPSS
11.6%
2021 CWE-384 2 PoCs

In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

CVE-2021-38094
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.

CVE-2021-45257
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An infinite loop vulnerability exists in nasm 2.16rc0 via the gpaste_tokens function.

CVE-2021-34430
Eclipse TinyDTLS General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-338 1 PoC

Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

CVE-2021-43495
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
54.6%
2021 0 PoCs

AlquistManager branch as of commit 280d99f43b11378212652e75f6f3159cde9c1d36 is affected by a directory traversal vulnerability in alquist/IO/input.py. This attack can cause the disclosure of critical secrets stored anywhere on the system and can significantly aid in getting remote code access.

CVE-2021-25156
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
9.5%
2021 1 PoC

A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.6 and below; Aruba Instant 8.7.x: 8.7.1.0 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2021-37145
Software Genérico General
N/A
UNKNOWN
EPSS
3.1%
2021 1 PoC

A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-25434
Tizen wearable devices General
N/A
UNKNOWN
EPSS
1.1%
2021 CWE-20 1 PoC

Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware download mode.

CVE-2021-26833
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attacker who can locally read user's files obtain JWT tokens for user's account due to insufficient cache clearing mechanisms. A threat actor can obtain sensitive user data by decoding the tokens as JWT is signed and encoded, not encrypted.

CVE-2021-44509
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, attackers can cause an integer underflow of the size of calls to memset in op_fnj3 in sr_port/op_fnj3.c in order to cause a segmentation fault and crash the application.

CVE-2021-28682
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large grpc-timeout value leads to unexpected timeout calculations.

CVE-2021-31159
Software Genérico General
N/A
UNKNOWN
EPSS
24.3%
2021 4 PoCs

Zoho ManageEngine ServiceDesk Plus MSP before 10519 is vulnerable to a User Enumeration bug due to improper error-message generation in the Forgot Password functionality, aka SDPMSP-15732.

CVE-2021-25759
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user.

CVE-2021-25412
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-284 1 PoC

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

CVE-2021-22887
PSA5000, PSA7000 General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-506 1 PoC

A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to compromise BIOS firmware. This vulnerability can be exploited only as part of an attack chain. Before an attacker can compromise the BIOS, they must exploit the device.

CVE-2021-0334
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In onTargetSelected of ResolverActivity.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-163358811

CVE-2021-26378
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

CVE-2021-25447
Smart Things General
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-284 1 PoC

Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.