3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-1109
Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX, Jetson Nano, Jetson Nano 2GB, Jetson TX1. General
7.2
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA camera firmware contains a multistep, timing-related vulnerability where an unauthorized modification by camera resources may result in loss of data integrity or denial of service across several streams.

CVE-2021-33552
E2 Series General
7.2
HIGH
EPSS
84.0%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42378
busybox General
7.2
HIGH
EPSS
0.2%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function

CVE-2021-39115
Jira Service Desk Server General
7.2
HIGH
EPSS
25.7%
2021 CWE-96 1 PoC

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

CVE-2021-25479
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.2%
2021 CWE-122 1 PoC

A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-33547
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42379
busybox General
7.2
HIGH
EPSS
0.2%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function

CVE-2021-25500
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.0%
2021 CWE-20 1 PoC

A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

CVE-2021-42385
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function

CVE-2021-33544
E2 Series General ⚡ nuclei
7.2
HIGH
EPSS
94.2%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-33545
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the counter parameter which may allow an attacker to remotely execute arbitrary code.

CVE-2021-28203
BMC firmware for Z10PR-D16 General
7.2
HIGH
EPSS
1.7%
2021 CWE-78 1 PoC

The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.

CVE-2021-30166
P2/Z2/P3/Z3 IP camera firmware General
7.2
HIGH
EPSS
6.6%
2021 CWE-78 1 PoC

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

CVE-2021-33549
E2 Series General
7.2
HIGH
EPSS
88.7%
2021 CWE-121 2 PoCs

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the action parameter, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-25478
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.2%
2021 CWE-121 1 PoC

A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-36295
VNX Control Station General
7.2
HIGH
EPSS
0.9%
2021 CWE-78 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

CVE-2021-22900
🔥 KEV Pulse Secure Secure General
7.2
HIGH
EPSS
0.7%
2021 CWE-94 1 PoC

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

CVE-2021-33546
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the name parameter, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-29439
grav-plugin-admin General
7.2
HIGH
EPSS
0.7%
2021 CWE-863 1 PoC

The Grav admin plugin prior to version 1.10.11 does not correctly verify caller's privileges. As a consequence, users with the permission `admin.login` can install third-party plugins and their dependencies. By installing the right plugin, an attacker can obtain an arbitrary code execution primitive and elevate their privileges on the instance. The vulnerability has been addressed in version 1.10.11. As a mitigation blocking access to the `/admin` path from untrusted sources will reduce the probability of exploitation.

CVE-2021-33554
E2 Series General
7.2
HIGH
EPSS
87.4%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.