142 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2021-21551
🔥 KEV dbutil General
8.8
HIGH
EPSS
64.4%
2021 CWE-782 12 PoCs

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

CVE-2021-39144
🔥 KEV xstream General ⚡ nuclei
8.5
HIGH
EPSS
94.3%
2021 CWE-94 4 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVE-2021-1905
🔥 KEV Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
8.4
HIGH
EPSS
0.6%
2021 1 PoC

Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-33739
🔥 KEV Windows 10 Version 1909 Windows
8.4
HIGH
EPSS
19.0%
2021 2 PoCs

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-22555
🔥 KEV Linux Kernel General
8.3
HIGH
EPSS
86.3%
2021 CWE-787 16 PoCs

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVE-2021-32648
🔥 KEV october Web ⚡ nuclei
8.2
HIGH
EPSS
93.0%
2021 CWE-287 2 PoCs

octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5.

CVE-2021-27877
🔥 KEV Software Genérico General
8.2
HIGH
EPSS
45.5%
2021 1 PoC

An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized access to an Agent and execute privileged commands.

CVE-2021-27876
🔥 KEV Software Genérico General
8.1
HIGH
EPSS
1.1%
2021 1 PoC

An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access and complete the authentication process. Subsequently, the client can execute data management protocol commands on the authenticated connection. By using crafted input parameters in one of these commands, an attacker can access an arbitrary file on the system using System privile

CVE-2021-34486
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
36.5%
2021 2 PoCs

Windows Event Tracing Elevation of Privilege Vulnerability

CVE-2021-3156
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
92.5%
2021 91 PoCs

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

CVE-2021-42292
🔥 KEV Microsoft Office 2019 General
7.8
HIGH
EPSS
35.5%
2021 1 PoC

Microsoft Excel Security Feature Bypass Vulnerability

CVE-2021-38648
🔥 KEV Open Management Infrastructure General
7.8
HIGH
EPSS
31.8%
2021 1 PoC

Open Management Infrastructure Elevation of Privilege Vulnerability

CVE-2021-30860
🔥 KEV macOS General
7.8
HIGH
EPSS
70.6%
2021 8 PoCs

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2021-28310
🔥 KEV Windows 10 Version 1803 Windows
7.8
HIGH
EPSS
54.0%
2021 1 PoC

Win32k Elevation of Privilege Vulnerability

CVE-2021-1647
🔥 KEV Microsoft System Center Endpoint Protection General
7.8
HIGH
EPSS
77.4%
2021 2 PoCs

Microsoft Defender Remote Code Execution Vulnerability

CVE-2021-36955
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
20.7%
2021 1 PoC

Windows Common Log File System Driver Elevation of Privilege Vulnerability