3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-3141
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In Unisys Stealth (core) before 6.0.025.0, the Keycloak password is stored in a recoverable format that might be accessible by a local attacker, who could gain access to the Management Server and change the Stealth configuration.

CVE-2021-3739
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-476 2 PoCs

A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.

CVE-2021-43194
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

CVE-2021-28950
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.

CVE-2021-27224
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.

CVE-2021-26339
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated by compilers.

CVE-2021-44132
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2021 1 PoC

A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers to execute arbitrary commands via a crafted file.

CVE-2021-43289
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into an arbitrary directory of a GoCD server, but does not control the filename.

CVE-2021-0315
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-169763814.

CVE-2021-25949
set-getter General
N/A
UNKNOWN
EPSS
2.3%
2021 1 PoC

Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.

CVE-2021-26705
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.

CVE-2021-3004
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

CVE-2021-20066
JSDom General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious web page when script execution is enabled.

CVE-2021-20294
binutils General
N/A
UNKNOWN
EPSS
22.7%
2021 CWE-787 1 PoC

A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.

CVE-2021-25418
Samsung Internet General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-269 1 PoC

Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

CVE-2021-28958
Software Genérico General
N/A
UNKNOWN
EPSS
48.9%
2021 2 PoCs

Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.

CVE-2021-43439
Software Genérico General
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

CVE-2021-0328
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In onBatchScanReports and deliverBatchScan of GattService.java, there is a possible way to retrieve Bluetooth scan results without permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-172670415

CVE-2021-29647
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.

CVE-2021-3744
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-401 1 PoC

A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808.