3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-32459
Trend Micro Home Network Security General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.

CVE-2021-44917
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.

CVE-2021-41637
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

CVE-2021-3339
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2021 1 PoC

ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.

CVE-2021-32012
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js (issue 1 of 2).

CVE-2021-20075
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.

CVE-2021-43517
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

FOSCAM Camera FI9805E with firmware V4.02.R12.00018510.10012.143900.00000 contains a backdoor that opens Telnet port when special command is sent on port 9530.

CVE-2021-28960
Software Genérico General
N/A
UNKNOWN
EPSS
6.7%
2021 1 PoC

Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handling of an input command in on-demand operations.

CVE-2021-44501
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause calls to ZRead to crash due to a NULL pointer dereference.

CVE-2021-30183
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when running import or export processes, the password used to encrypt and decrypt sensitive values would be written to the logs in plaintext.

CVE-2021-44503
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a call to va_arg on an empty variadic parameter list, most likely causing a memory segmentation fault.

CVE-2021-44505
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.

CVE-2021-3715
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-416 1 PoC

A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2021-0326
Android General
N/A
UNKNOWN
EPSS
13.1%
2021 4 PoCs

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172937525

CVE-2021-33324
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Layout module in Liferay Portal 7.1.0 through 7.3.1, and Liferay DXP 7.1 before fix pack 20, and 7.2 before fix pack 5, does not properly check permission of pages, which allows remote authenticated users without view permission of a page to view the page via a site's page administration.

CVE-2021-34824
Software Genérico General
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

Istio (1.8.x, 1.9.0-1.9.5 and 1.10.0-1.10.1) contains a remotely exploitable vulnerability where credentials specified in the Gateway and DestinationRule credentialName field can be accessed from different namespaces.

CVE-2021-43708
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.

CVE-2021-25445
Samsung Internet General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-287 1 PoC

Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.

CVE-2021-45908
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in gif2apng 1.9. There is a stack-based buffer overflow involving a while loop. An attacker has little influence over the data written to the stack, making it unlikely that the flow of control can be subverted.

CVE-2021-44495
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in YottaDB through r1.32 and V7.0-000 and FIS GT.M through V7.0-000. Using crafted input, an attacker can cause a NULL pointer dereference after calls to ZPrint.