3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-2282
VM VirtualBox Database
7.1
HIGH
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base S

CVE-2021-25388
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2021 CWE-926 2 PoCs

Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

CVE-2021-26397
3rd Gen AMD EPYC™ General
7.1
HIGH
EPSS
0.0%
2021 1 PoC

Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.

CVE-2021-25346
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.6%
2021 2 PoCs

A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

CVE-2021-37859
Mattermost Web
7.1
HIGH
EPSS
45.1%
2021 CWE-79 1 PoC

Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.

CVE-2021-26088
Fortinet FSSO Windows DC Agent, FSSO Windows CA Networking Windows
7.1
HIGH
EPSS
5.5%
2021 1 PoC

An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall policy and access the protected network via sending specifically crafted UDP login notification packets.

CVE-2021-40413
Software Genérico Web
7.1
HIGH
EPSS
0.2%
2021 CWE-284 1 PoC

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-29447
wordpress-develop Web Windows
7.1
HIGH
EPSS
90.0%
2021 CWE-611 23 PoCs

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.

CVE-2021-47921
Free Photo & Video Vault - WiFi Transfe‪r General
7.1
HIGH
EPSS
0.6%
2021 CWE-22 1 PoC

Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipulate application path requests and access sensitive system files. Attackers can exploit the vulnerability without privileges to retrieve environment variables and access unauthorized system paths.

CVE-2021-4166
vim/vim General
7.1
HIGH
EPSS
0.4%
2021 CWE-125 1 PoC

vim is vulnerable to Out-of-bounds Read

CVE-2021-2286
VM VirtualBox Database
7.1
HIGH
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data.

CVE-2021-1091
NVIDIA GPU Display Driver Windows
7.1
HIGH
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.

CVE-2021-31883
Capital Embedded AR Classic 431-422 Web
7.1
HIGH
EPSS
1.4%
2021 CWE-119 1 PoC

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP ACK message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions. (FSMD-2021-0013)

CVE-2021-21401
nanopb General
7.1
HIGH
EPSS
0.2%
2021 CWE-763 2 PoCs

Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, decoding a specifically formed message can cause invalid `free()` or `realloc()` calls if the message type contains an `oneof` field, and the `oneof` directly contains both a pointer field and a non-pointer field. If the message data first contains the non-pointer field and then the pointer field, the data of the non-pointer field is incorrectly treated as if it was a pointer value. Such message data rarely occurs in normal messages, but it is a concern when untrusted data is par

CVE-2021-47872
SEO Panel Web Database
7.0
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

SEO Panel versions prior to 4.9.0 contain a blind SQL injection vulnerability in the archive.php page that allows authenticated attackers to manipulate database queries through the 'order_col' parameter. Attackers can use sqlmap to exploit the vulnerability and extract database information by injecting malicious SQL code into the order column parameter.

CVE-2021-37942
Elastic APM Java Agent General
7.0
HIGH
EPSS
0.1%
2021 CWE-269 1 PoC

A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious plugin to an application running the APM Java agent. By using this vulnerability, an attacker could execute code at a potentially higher level of permissions than their user typically has access to.

CVE-2021-29667
Spectrum Scale General
7.0
HIGH
EPSS
0.3%
2021 1 PoC

IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 199403.

CVE-2021-1782
🔥 KEV iOS and iPadOS General
7.0
HIGH
EPSS
5.9%
2021 2 PoCs

A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..

CVE-2021-26863
Windows 10 Version 1803 Windows
7.0
HIGH
EPSS
0.2%
2021 1 PoC

Windows Win32k Elevation of Privilege Vulnerability

CVE-2021-31799
Software Genérico General
7.0
HIGH
EPSS
0.4%
2021 1 PoC

In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.