1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-36942
🔥 KEV Windows Server 2019 Windows
7.5
HIGH
EPSS
93.7%
2021 1 PoC

Windows LSA Spoofing Vulnerability

CVE-2021-42141
Software Genérico Windows
7.5
HIGH
EPSS
0.1%
2021 1 PoC

An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could complete with different epoch numbers in the packets Client_Hello, Client_key_exchange, and Change_cipher_spec, which may cause denial of service.

CVE-2021-29703
DB2 for Linux, UNIX and Windows Windows
7.5
HIGH
EPSS
0.6%
2021 1 PoC

Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server terminates abnormally when executing a specially crafted SELECT statement. IBM X-Force ID: 200659.

CVE-2021-24881
Passster Web Windows
7.5
HIGH
EPSS
1.1%
2021 1 PoC

The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

CVE-2021-40476
Windows 10 Version 1809 DevOps Windows
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Windows AppContainer Elevation Of Privilege Vulnerability

CVE-2021-23335
is-user-valid Windows
7.5
HIGH
EPSS
0.2%
2021 1 PoC

All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or information exposure.

CVE-2021-39316
ZoomSounds - WordPress Wave Audio Player with Playlist Web Windows ⚡ nuclei
7.5
HIGH
EPSS
93.5%
2021 CWE-22 2 PoCs

The Zoomsounds plugin <= 6.45 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the `dzsap_download` action using directory traversal in the `link` parameter.

CVE-2021-43893
Windows 10 Version 1809 Windows
7.5
HIGH
EPSS
6.8%
2021 1 PoC

Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability

CVE-2021-39312
True Ranker Web Windows ⚡ nuclei
7.5
HIGH
EPSS
90.8%
2021 CWE-22 1 PoC

The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

CVE-2021-4448
Kaswara Modern VC Addons Web Windows ⚡ nuclei
7.3
HIGH
EPSS
48.9%
2021 CWE-862 0 PoCs

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.

CVE-2021-23878
Endpoint Security (ENS) for Windows Windows
7.3
HIGH
EPSS
0.2%
2021 CWE-312 1 PoC

Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the local user has to access the relevant memory location immediately after an ENS administrator has made a configuration change through the console on their machine

CVE-2021-33766
🔥 KEV Microsoft Exchange Server 2019 Cumulative Update 9 Windows ⚡ nuclei
7.3
HIGH
EPSS
93.6%
2021 2 PoCs

Microsoft Exchange Server Information Disclosure Vulnerability

CVE-2021-31843
McAfee Endpoint Security (ENS) for WIndows Windows
7.3
HIGH
EPSS
0.0%
2021 CWE-59 1 PoC

Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.

CVE-2021-31840
McAfee Agent for Windows Windows
7.3
HIGH
EPSS
0.0%
2021 CWE-427 1 PoC

A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.

CVE-2021-42955
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.

CVE-2021-34423
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Windows
7.3
HIGH
EPSS
0.4%
2021 1 PoC

A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4, Zoom Client for Meetings for Chrome OS before version 5.0.1, Zoom Rooms for Conference Room (for Android, AndroidBali, macOS, and Windows) before version 5.8.3, Controllers for Zoom Rooms (for Android, iOS, and Windows) before version 5.8.3, Zoom VDI Windows Meeting Client before version 5.8.

CVE-2021-24151
WP Editor Web Database Windows
7.2
HIGH
EPSS
0.5%
2021 1 PoC

The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.

CVE-2021-24942
Menu Item Visibility Control Web Windows
7.2
HIGH
EPSS
1.0%
2021 1 PoC

The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment.

CVE-2021-24786
Download Monitor Web Database Windows ⚡ nuclei
7.2
HIGH
EPSS
2.2%
2021 CWE-89 1 PoC

The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue

CVE-2021-39352
Catch Themes Demo Import Web Windows
7.2
HIGH
EPSS
75.6%
2021 CWE-434 3 PoCs

The Catch Themes Demo Import WordPress plugin is vulnerable to arbitrary file uploads via the import functionality found in the ~/inc/CatchThemesDemoImport.php file, in versions up to and including 1.7, due to insufficient file type validation. This makes it possible for an attacker with administrative privileges to upload malicious files that can be used to achieve remote code execution.