1363 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2021-1091
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.

CVE-2021-42110
Software Genérico Windows
7.1
HIGH
EPSS
0.1%
2021 2 PoCs

An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.

CVE-2021-29447
wordpress-develop Web Windows
7.1
HIGH
EPSS
90.0%
2021 CWE-611 23 PoCs

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.

CVE-2021-1092
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.

CVE-2021-26088
Fortinet FSSO Windows DC Agent, FSSO Windows CA Networking Windows
7.1
HIGH
EPSS
5.5%
2021 1 PoC

An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.

CVE-2021-1090
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVE-2021-36949
Microsoft Azure Active Directory Connect 1.X.Y.Z Cloud Windows
7.1
HIGH
EPSS
0.8%
2021 1 PoC

Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability

CVE-2021-43890
🔥 KEV App Installer Windows
7.1
HIGH
EPSS
25.2%
2021 3 PoCs

We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a malicious attachment to be used in phishing campaigns. The attacker would then have to convince the user to open the specially crafted attachment. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative

CVE-2021-26863
Windows 10 Version 1803 Windows
7.0
HIGH
EPSS
0.2%
2021 1 PoC

Windows Win32k Elevation of Privilege Vulnerability

CVE-2021-34480
Windows 10 Version 1809 Windows
6.8
MEDIUM
EPSS
3.1%
2021 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2021-35567
Java SE JDK and JRE Database Windows
6.8
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional pr

CVE-2021-47759
MTPutty Networking Windows
6.8
MEDIUM
EPSS
0.0%
2021 CWE-522 1 PoC

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes, exposing plaintext SSH credentials.

CVE-2021-47771
RDP Manager Windows
6.8
MEDIUM
EPSS
0.0%
2021 CWE-770 2 PoCs

RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attackers can add oversized entries in Verbindungsname and Server fields to permanently freeze and crash the software, potentially requiring full reinstallation.

CVE-2021-23880
Endpoint Security (ENS) for Windows Windows
6.7
MEDIUM
EPSS
0.1%
2021 CWE-269 1 PoC

Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows authenticated local administrator user to perform an uninstallation of the anti-malware engine via the running of a specific command with the correct parameters.

CVE-2021-41276
tuleap Windows
6.7
MEDIUM
EPSS
0.5%
2021 CWE-74 1 PoC

Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected versions Tuleap does not sanitize properly the search filter built from the ldap_id attribute of a user during the daily synchronization. A malicious user could force accounts to be suspended or take over another account by forcing the update of the ldap_uid attribute. Note that the malicious user either need to have site administrator capability on the Tuleap instance or be an LDAP operator with the capability to create/modify account. The Tuleap instance needs to have the LD

CVE-2021-23877
McAfee Total Protection (MTP) Windows
6.7
MEDIUM
EPSS
0.0%
2021 CWE-269 1 PoC

Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.

CVE-2021-47881
dataSIMS Avionics ARINC Windows
6.7
MEDIUM
EPSS
0.0%
2021 CWE-121 1 PoC

dataSIMS Avionics ARINC 664-1 version 4.5.3 contains a local buffer overflow vulnerability that allows attackers to overwrite memory by manipulating the milstd1553result.txt file. Attackers can craft a malicious file with carefully constructed payload and alignment sections to potentially execute arbitrary code on the Windows system.

CVE-2021-31207
🔥 KEV Microsoft Exchange Server 2013 Cumulative Update 23 Windows
6.6
MEDIUM
EPSS
93.8%
2021 1 PoC

Microsoft Exchange Server Security Feature Bypass Vulnerability

CVE-2021-42550
logback Windows
6.6
MEDIUM
EPSS
2.7%
2021 CWE-502 2 PoCs

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

CVE-2021-41349
Microsoft Exchange Server 2013 Cumulative Update 23 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
91.1%
2021 2 PoCs

Microsoft Exchange Server Spoofing Vulnerability