3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-39115
Jira Service Desk Server General
7.2
HIGH
EPSS
25.7%
2021 CWE-96 1 PoC

Affected versions of Atlassian Jira Service Management Server and Data Center allow remote attackers with "Jira Administrators" access to execute arbitrary Java code or run arbitrary system commands via a Server_Side Template Injection vulnerability in the Email Template feature. The affected versions are before version 4.13.9, and from version 4.14.0 before 4.18.0.

CVE-2021-36295
VNX Control Station General
7.2
HIGH
EPSS
0.9%
2021 CWE-78 1 PoC

Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.

CVE-2021-30166
P2/Z2/P3/Z3 IP camera firmware General
7.2
HIGH
EPSS
6.6%
2021 CWE-78 1 PoC

The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the privileged permission.

CVE-2021-33547
E2 Series General
7.2
HIGH
EPSS
19.3%
2021 CWE-121 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to a stack-based buffer overflow condition in the profile parameter which may allow an attacker to remotely execute arbitrary code.

CVE-2021-42382
busybox General
7.2
HIGH
EPSS
0.3%
2021 CWE-416 2 PoCs

A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function

CVE-2021-21885
Lantronix Web
7.2
HIGH
EPSS
0.3%
2021 CWE-22 1 PoC

A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2021-25500
Samsung Mobile Devices General
7.2
HIGH
EPSS
0.0%
2021 CWE-20 1 PoC

A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

CVE-2021-33551
E2 Series General
7.2
HIGH
EPSS
84.0%
2021 CWE-78 1 PoC

Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2021-40425
Secure Anywhere General
7.1
HIGH
EPSS
0.0%
2021 CWE-125 1 PoC

An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. An IOCTL_B03 request with specific invalid data causes a similar issue in the device driver WRCore_x64. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2021-45448
Pentaho Business Analytics Server General
7.1
HIGH
EPSS
0.4%
2021 CWE-22 1 PoC

Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user-supplied path to access resources that are out of bounds.  The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.  By using special eleme

CVE-2021-1257
Cisco Digital Network Architecture Center (DNA Center) Web Networking
7.1
HIGH
EPSS
0.1%
2021 CWE-352 1 PoC

A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness or consent. The vulnerability is due to insufficient CSRF protections for the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a web-based management user to follow a specially crafted link. A successful exploit could allow the attacker to perform arbitrary

CVE-2021-47766
Kmaleon Web Database
7.1
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Kmaleon 1.1.0.205 contains an authenticated SQL injection vulnerability in the 'tipocomb' parameter of kmaleonW.php that allows attackers to manipulate database queries. Attackers can exploit this vulnerability using boolean-based, error-based, and time-based blind SQL injection techniques to potentially extract or manipulate database information.

CVE-2021-3881
bfabiszewski/libmobi General
7.1
HIGH
EPSS
0.4%
2021 CWE-125 1 PoC

libmobi is vulnerable to Out-of-bounds Read

CVE-2021-3831
gnuboard/gnuboard5 Web ⚡ nuclei
7.1
HIGH
EPSS
26.6%
2021 CWE-79 2 PoCs

gnuboard5 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-2283
VM VirtualBox Database
7.1
HIGH
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base S

CVE-2021-27272
ProSAFE Network Management System General
7.1
HIGH
EPSS
69.0%
2021 CWE-22 1 PoC

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ReportTemplateController class. When parsing the path parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12123.

CVE-2021-1090
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVE-2021-27276
ProSAFE Network Management System General
7.1
HIGH
EPSS
59.0%
2021 CWE-22 1 PoC

This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the MibController class. When parsing the realName parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-12122.

CVE-2021-1935
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables General
7.1
HIGH
EPSS
0.0%
2021 1 PoC

Possible null pointer dereference due to lack of validation check for passed pointer during key import in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-25356
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2021 CWE-20 3 PoCs

An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.