1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-31850
McAfee Database Security (DBSec) Windows
6.1
MEDIUM
EPSS
0.3%
2021 CWE-552 1 PoC

A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator to trigger a denial-of-service attack against the DBS server. The configuration of Archiving through the User interface incorrectly allowed the creation of directories and files in Windows system directories and other locations where sensitive data could be overwritten. The former could lead to a DoS, whilst the latter could lead to data destruction on the DBS server.

CVE-2021-24870
WP Fastest Cache Web Windows
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

The WP Fastest Cache WordPress plugin before 0.9.5 is lacking a CSRF check in its wpfc_save_cdn_integration AJAX action, and does not sanitise and escape some the options available via the action, which could allow attackers to make logged in high privilege users call it and set a Cross-Site Scripting payload

CVE-2021-25509
Samsung Flow Windows
5.9
MEDIUM
EPSS
0.1%
2021 CWE-20 1 PoC

A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.

CVE-2021-38878
QRadar SIEM Windows
5.9
MEDIUM
EPSS
0.3%
2021 1 PoC

IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity authentication. IBM X-Force ID: 208756.

CVE-2021-3882
ledgersmb/ledgersmb Web Windows
5.9
MEDIUM
EPSS
0.1%
2021 CWE-614 1 PoC

LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the LedgerSMB server is behind a reverse proxy. By tricking a user to use an unencrypted connection (HTTP), an attacker may be able to obtain the authentication data by capturing network traffic. LedgerSMB 1.8 and newer switched from Basic authentication to using cookie authentication with encrypted cookies. Although an attacker can't access the information inside the cookie, nor the password of the user, possession of the cookie is enough to access the application as the user from

CVE-2021-25736
Kubernetes DevOps Windows
5.8
MEDIUM
EPSS
0.1%
2021 1 PoC

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.

CVE-2021-31836
McAfee Agent for Windows Windows
5.6
MEDIUM
EPSS
0.1%
2021 CWE-269 1 PoC

Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user to gain access to sensitive information. The utility was able to be run from any location on the file system and by a low privileged user.

CVE-2021-1116
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.0%
2021 CWE-476 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

CVE-2021-24084
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.0%
2021 2 PoCs

Windows Mobile Device Management Information Disclosure Vulnerability

CVE-2021-31955
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.1%
2021 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2021-1096
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.

CVE-2021-36873
iQ Block Country Web Windows ⚡ nuclei
5.5
MEDIUM
EPSS
1.8%
2021 CWE-79 0 PoCs

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

CVE-2021-1699
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows (modem.sys) Information Disclosure Vulnerability

CVE-2021-38926
DB2 for Linux, UNIX and Windows Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.

CVE-2021-31184
Windows 10 Version 1803 Windows
5.5
MEDIUM
EPSS
2.4%
2021 1 PoC

Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability

CVE-2021-33602
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Cloud Protection for Salesforce Cloud Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

CVE-2021-1656
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
1.7%
2021 1 PoC

TPM Device Driver Information Disclosure Vulnerability

CVE-2021-24098
Windows 10 Version 2004 Windows
5.5
MEDIUM
EPSS
2.0%
2021 1 PoC

Windows Console Driver Denial of Service Vulnerability

CVE-2021-1095
NVIDIA GPU Display Driver Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.

CVE-2021-23886
McAfee Data Loss Prevention (DLP) Endpoint for Windows Windows
5.5
MEDIUM
EPSS
0.0%
2021 CWE-755 2 PoCs

Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.