1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-28313
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.5%
2021 2 PoCs

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

CVE-2021-26868
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
4.9%
2021 1 PoC

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2021-35538
VM VirtualBox Database Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.28. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability does not apply to Windows systems. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H

CVE-2021-31165
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-1366
Cisco AnyConnect Secure Mobility Client Networking Windows
7.8
HIGH
EPSS
0.6%
2021 CWE-347 1 PoC

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affect

CVE-2021-28322
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.7%
2021 2 PoCs

Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability

CVE-2021-23887
McAfee Data Loss Prevention (DLP) Endpoint for Windows Windows
7.8
HIGH
EPSS
0.0%
2021 CWE-269 2 PoCs

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.

CVE-2021-31168
Windows 10 Version 2004 DevOps Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2021-26882
Windows 10 Version 1803 Web Windows
7.8
HIGH
EPSS
4.2%
2021 2 PoCs

Remote Access API Elevation of Privilege Vulnerability

CVE-2021-42956
Software Genérico Windows
7.8
HIGH
EPSS
0.2%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop Binary fixed in 10.1.2132.6 is affected by a sensitive information disclosure vulnerability. Due to improper privilege management, the process launches as the logged in user, so memory dump can be done by non-admin also. Remotely, an attacker can dump all sensitive information including DB Connection string, entire IT infrastructure details, commands executed by IT admin including credentials, secrets, private keys and more.

CVE-2021-34486
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
36.5%
2021 2 PoCs

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-27086
Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
0.3%
2021 1 PoC

Windows Services and Controller App Elevation of Privilege Vulnerability

CVE-2021-39351
WP Bannerize Web Database Windows
7.7
HIGH
EPSS
0.8%
2021 CWE-89 1 PoC

The WP Bannerize WordPress plugin is vulnerable to authenticated SQL injection via the id parameter found in the ~/Classes/wpBannerizeAdmin.php file which allows attackers to exfiltrate sensitive information from vulnerable sites. This issue affects versions 2.0.0 - 4.0.2.

CVE-2021-21402
jellyfin Windows ⚡ nuclei
7.7
HIGH
EPSS
90.5%
2021 CWE-22 4 PoCs

Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file read from a Jellyfin server's file system. This issue is more prevalent when Windows is used as the host OS. Servers that are exposed to the public Internet are potentially at risk. This is fixed in version 10.7.1. As a workaround, users may be able to restrict some access by enforcing strict security permissions on their filesystem, however, it is recommended to update as soon as possible.

CVE-2021-31854
McAfee Agent for Windows Windows
7.7
HIGH
EPSS
0.3%
2021 CWE-78 1 PoC

A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment feature located in the System Tree. An attacker may exploit the vulnerability to obtain a reverse shell which can lead to privilege escalation to obtain root privileges.

CVE-2021-39201
wordpress-develop Web Database Windows
7.6
HIGH
EPSS
0.5%
2021 CWE-79 3 PoCs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. This bypasses the restrictions imposed on users who do not have the permission to post `unfiltered_html`. ### Patches This has been patched in WordPress 5.8, and will be pushed to older versions via minor releases (automatic updates). It's strongly recommended that you keep auto-updates enabled to receive the fix. ### References https://wordpress.org/

CVE-2021-31950
Microsoft SharePoint Enterprise Server 2016 Windows
7.6
HIGH
EPSS
1.7%
2021 1 PoC

Microsoft SharePoint Server Spoofing Vulnerability

CVE-2021-42141
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2021 1 PoC

An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause denial of service.

CVE-2021-36942
🔥 KEV Windows Server 2019 Windows
7.5
HIGH
EPSS
93.7%
2021 1 PoC

Windows LSA Spoofing Vulnerability