1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-47805
Disk Savvy Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Disk Savvy 13.6.14 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in service binaries to inject malicious executables that will be run with elevated LocalSystem privileges.

CVE-2021-47882
FreeLAN Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

FreeLAN 2.2 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with elevated LocalSystem privileges during service startup.

CVE-2021-47845
Spy Emergency Windows
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to inject malicious code during system startup or service restart.

CVE-2021-1051
NVIDIA GPU Display Driver Windows
8.4
HIGH
EPSS
0.0%
2021 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.

CVE-2021-33739
🔥 KEV Windows 10 Version 1909 Windows
8.4
HIGH
EPSS
19.0%
2021 2 PoCs

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-37713
node-tar Windows
8.2
HIGH
EPSS
0.3%
2021 CWE-22 1 PoC

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of the extraction target directory is not extracted. This is, in part, accomplished by sanitizing absolute paths of entries within the archive, skipping archive entries that contain `..` path portions, and resolving the sanitized paths against the extraction target directory. This logic was insufficient on Windows systems when extracting tar files that containe

CVE-2021-31844
McAfee Data Loss Prevention (DLP) Endpoint for Windows Windows
8.2
HIGH
EPSS
0.1%
2021 CWE-120 1 PoC

A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a file. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

CVE-2021-31847
McAfee Agent for Windows Windows
8.2
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.

CVE-2021-41116
composer Web Windows
8.2
HIGH
EPSS
1.0%
2021 CWE-77 1 PoC

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs and WSL are not affected. The issue has been resolved in composer versions 1.10.23 and 2.1.9. There are no workarounds for this issue.

CVE-2021-23882
Endpoint Security (ENS) for Windows Windows
8.2
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows local administrators to prevent the installation of some ENS files by placing carefully crafted files where ENS will be installed. This is only applicable to clean installations of ENS as the Access Control rules will prevent modification prior to up an upgrade.

CVE-2021-31841
McAfee Agent for Windows Windows
8.2
HIGH
EPSS
0.0%
2021 CWE-426 1 PoC

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.

CVE-2021-39341
OptinMonster Web Windows ⚡ nuclei
8.2
HIGH
EPSS
44.3%
2021 CWE-285 0 PoCs

The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.

CVE-2021-43217
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
23.7%
2021 1 PoC

Windows Encrypting File System (EFS) Remote Code Execution Vulnerability

CVE-2021-44223
Software Genérico Web Windows
8.1
HIGH
EPSS
27.5%
2021 1 PoC

WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execute arbitrary code via a supply-chain attack against WordPress installations that use any plugin for which the slug satisfies the naming constraints of the WordPress.org Plugin Directory but is not yet present in that directory.

CVE-2021-2279
VM VirtualBox Database Windows
8.1
HIGH
EPSS
7.6%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2021-21389
BuddyPress Web Windows ⚡ nuclei
8.1
HIGH
EPSS
93.3%
2021 CWE-863 2 PoCs

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVE-2021-34470
Microsoft Exchange Server 2013 Cumulative Update 23 Windows
8.0
HIGH
EPSS
4.7%
2021 2 PoCs

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2021-21300
git Windows
8.0
HIGH
EPSS
64.5%
2021 CWE-59 15 PoCs

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March

CVE-2021-33542
Automation Worx Software Suite Windows
7.8
HIGH
EPSS
0.5%
2021 CWE-824 1 PoC

Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get access to an original bus configuration file (*.bcp) to be able to manipulate data inside. After manipulation the attacker needs to exchange the original file by the manipulated one on the application programming workstation. Availability, integrity, or confidentiality of an applicatio