3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-35234
Orion Core Database
8.0
HIGH
EPSS
0.8%
2021 CWE-89 1 PoC

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

CVE-2021-30481
Software Genérico General
8.0
HIGH
EPSS
7.5%
2021 3 PoCs

Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

CVE-2021-23271
TIBCO EBX Web
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.12 and below.

CVE-2021-25961
SuiteCRM General
8.0
HIGH
EPSS
0.3%
2021 CWE-640 1 PoC

In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.

CVE-2021-41503
Software Genérico General
8.0
HIGH
EPSS
0.4%
2021 1 PoC

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-3968
vim/vim General
8.0
HIGH
EPSS
0.8%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-32003
SiteManager General
8.0
HIGH
EPSS
0.0%
2021 CWE-523 1 PoC

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

CVE-2021-25960
SuiteCRM General
8.0
HIGH
EPSS
0.5%
2021 CWE-1236 1 PoC

In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.

CVE-2021-39170
pimcore Web
8.0
HIGH
EPSS
0.0%
2021 CWE-116 1 PoC

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

CVE-2021-23273
TIBCO Spotfire Analyst Web Cloud
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.1

CVE-2021-25962
shuup General
8.0
HIGH
EPSS
0.4%
2021 CWE-1236 1 PoC

“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.

CVE-2021-3961
snipe/snipe-it Web
8.0
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-21300
git Windows
8.0
HIGH
EPSS
64.5%
2021 CWE-59 15 PoCs

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March

CVE-2021-21505
Dell EMC Integrated System for Microsoft Azure Stack Hub Cloud
8.0
HIGH
EPSS
5.4%
2021 CWE-255 2 PoCs

Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.

CVE-2021-35485
Software Genérico General
8.0
HIGH
EPSS
0.1%
2021 1 PoC

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.

CVE-2021-31581
Provisioning Manager Engine (PME) Database ⚡ nuclei
7.9
HIGH
EPSS
9.2%
2021 CWE-269 0 PoCs

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

CVE-2021-25361
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-22 2 PoCs

An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.

CVE-2021-25470
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-94 1 PoC

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

CVE-2021-25502
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

CVE-2021-2129
VM VirtualBox Database
7.9
HIGH
EPSS
0.1%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data