3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-37695
ckeditor4 Web
7.3
HIGH
EPSS
0.7%
2021 CWE-79 3 PoCs

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

CVE-2021-23402
record-like-deep-assign General
7.3
HIGH
EPSS
0.5%
2021 1 PoC

All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.

CVE-2021-22261
GitLab DevOps Web
7.3
HIGH
EPSS
0.2%
2021 1 PoC

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVE-2021-34605
XD/E Series PLC Program Tool General
7.3
HIGH
EPSS
0.6%
2021 CWE-23 1 PoC

A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.

CVE-2021-3984
vim/vim General
7.3
HIGH
EPSS
0.2%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-42955
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.

CVE-2021-4170
janeczku/calibre-web Web
7.3
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-3903
vim/vim General
7.3
HIGH
EPSS
0.4%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-4448
Kaswara Modern VC Addons Web Windows ⚡ nuclei
7.3
HIGH
EPSS
48.9%
2021 CWE-862 0 PoCs

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.

CVE-2021-38410
Platform Common Services (PCS) Portal General
7.3
HIGH
EPSS
0.1%
2021 1 PoC

AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijacking through an uncontrolled search path element, which may allow an attacker control to one or more locations in the search path.

CVE-2021-32549
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.

CVE-2021-23682
litespeed.js General
7.3
HIGH
EPSS
5.4%
2021 2 PoCs

This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.

CVE-2021-23419
open-graph General
7.3
HIGH
EPSS
0.4%
2021 1 PoC

This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.

CVE-2021-23374
ps-visitor General
7.3
HIGH
EPSS
0.8%
2021 1 PoC

This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-4069
vim/vim General
7.3
HIGH
EPSS
0.2%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-31843
McAfee Endpoint Security (ENS) for WIndows Windows
7.3
HIGH
EPSS
0.0%
2021 CWE-59 1 PoC

Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.

CVE-2021-33766
🔥 KEV Microsoft Exchange Server 2019 Cumulative Update 9 Windows ⚡ nuclei
7.3
HIGH
EPSS
93.6%
2021 2 PoCs

Microsoft Exchange Server Information Disclosure Vulnerability

CVE-2021-23518
cached-path-relative Web
7.3
HIGH
EPSS
0.6%
2021 3 PoCs

The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set as {} instead of Object.create(null) in the cachedPathRelative function, which allows access to the parent prototype properties when the object is used to create the cached relative path. When using the origin path as __proto__, the attribute of the object is accessed instead of a path. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-CACHEDPATHRELATIVE-72573

CVE-2021-23878
Endpoint Security (ENS) for Windows Windows
7.3
HIGH
EPSS
0.2%
2021 CWE-312 1 PoC

Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the local user has to access the relevant memory location immediately after an ENS administrator has made a configuration change through the console on their machine

CVE-2021-32550
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.