3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-20162
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 stores credentials in plaintext. Usernames and passwords are stored in plaintext in the config files on the device. For example, /etc/config/cameo contains the admin password in plaintext.

CVE-2021-36751
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ENC DataVault 7.2.3 and before, and OEM versions, use an encryption algorithm that is vulnerable to data manipulation (without knowledge of the key). This is called ciphertext malleability. There is no data integrity mechanism to detect this manipulation.

CVE-2021-36981
Software Genérico General
N/A
UNKNOWN
EPSS
16.5%
2021 1 PoC

In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

CVE-2021-41638
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.

CVE-2021-27114
Software Genérico General
N/A
UNKNOWN
EPSS
2.6%
2021 1 PoC

An issue was discovered in D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/addassignment route, a very long text entry for the"'s_ip" and "s_mac" fields could lead to a Stack-Based Buffer Overflow and overwrite the return address.

CVE-2021-29266
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0.

CVE-2021-33488
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

chat in OX App Suite 7.10.5 has Improper Input Validation. A user can be redirected to a rogue OX Chat server via a development-related hook.

CVE-2021-34416
Zoom On-Premise Meeting Connector Controller, Zoom On-Premise Meeting Connector MMR, Zoom On-Premise Recording Connector, Zoom On-Premise Virtual Room Connector, Zoom On-Premise Virtual Room Connector Load Balancer General
N/A
UNKNOWN
EPSS
1.5%
2021 1 PoC

The network address administrative settings web portal for the Zoom on-premise Meeting Connector before version 4.6.360.20210325, Zoom on-premise Meeting Connector MMR before version 4.6.360.20210325, Zoom on-premise Recording Connector before version 3.8.44.20210326, Zoom on-premise Virtual Room Connector before version 4.4.6752.20210326, and Zoom on-premise Virtual Room Connector Load Balancer before version 2.5.5495.20210326 fails to validate input sent in requests to update the network configuration, which could lead to remote command injection on the on-premise image by the web portal adm

CVE-2021-26338
2nd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-284 1 PoC

Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.

CVE-2021-37605
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes.

CVE-2021-20127
Draytek VigorConnect General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This allows an authenticated user to arbitrarily delete files in any location on the target operating system with root privileges.

CVE-2021-40960
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
73.8%
2021 1 PoC

Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.

CVE-2021-20093
Wibu-Systems CodeMeter General
N/A
UNKNOWN
EPSS
8.2%
2021 2 PoCs

A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.

CVE-2021-42613
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly have other unspecified impact via a crafted text document.

CVE-2021-46312
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered IW44EncodeCodec.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.

CVE-2021-44659
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

Adding a new pipeline in GoCD server version 21.3.0 has a functionality that could be abused to do an un-intended action in order to achieve a Server Side Request Forgery (SSRF). NOTE: the vendor's position is that the observed behavior is not a vulnerability, because the product's design allows an admin to configure outbound requests

CVE-2021-20837
Movable Type General ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2021 12 PoCs

Movable Type 7 r.5002 and earlier (Movable Type 7 Series), Movable Type 6.8.2 and earlier (Movable Type 6 Series), Movable Type Advanced 7 r.5002 and earlier (Movable Type Advanced 7 Series), Movable Type Advanced 6.8.2 and earlier (Movable Type Advanced 6 Series), Movable Type Premium 1.46 and earlier, and Movable Type Premium Advanced 1.46 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. Note that all versions of Movable Type 4.0 or later including unsupported (End-of-Life, EOL) versions are also affected by this vulnerability.

CVE-2021-23924
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

CVE-2021-3564
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-415 3 PoCs

A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.

CVE-2021-0652
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In VectorDrawable::VectorDrawable of VectorDrawable.java, there is a possible way to introduce a memory corruption due to sharing of not thread-safe objects. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11Android ID: A-185178568