7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-38278
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the urls parameter in the saveParentControlInfo function.

CVE-2021-0399
Android General
N/A
UNKNOWN
EPSS
0.8%
2021 1 PoC

In qtaguid_untag of xt_qtaguid.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-176919394References: Upstream kernel

CVE-2021-45868
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 4 PoCs

In the Linux kernel before 5.15.3, fs/quota/quota_tree.c does not validate the block number in the quota tree (on disk). This can, for example, lead to a kernel/locking/rwsem.c use-after-free if there is a corrupted quota file.

CVE-2021-24588
SMS Alert Order Notifications – WooCommerce Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The SMS Alert Order Notifications WordPress plugin before 3.4.7 is affected by a cross site scripting (XSS) vulnerability in the plugin's setting page.

CVE-2021-22908
Pulse Connect Secure Windows
N/A
UNKNOWN
EPSS
22.7%
2021 CWE-120 1 PoC

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

CVE-2021-24153
Yoast SEO Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

A Stored Cross-Site Scripting vulnerability was discovered in the Yoast SEO WordPress plugin before 3.4.1, which had built-in blacklist filters which were blacklisting Parenthesis as well as several functions such as alert but bypasses were found.

CVE-2021-43483
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Access Control vulnerability exists in CLARO KAON CG3000 1.00.67 in the router configuration, which could allow a malicious user to read or update the configuraiton without authentication.

CVE-2021-29295
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Null Pointer Dereference vulnerability exists in D-Link DSP-W215 1.10, which could let a remote malicious user cause a denial of servie via usr/bin/lighttpd. It could be triggered by sending an HTTP request without URL in the start line directly to the device. NOTE: The DSP-W215 and all hardware revisions is considered End of Life and as such this issue will not be patched

CVE-2021-37371
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2021 3 PoCs

Online Student Admission System 1.0 is affected by an unauthenticated SQL injection bypass vulnerability in /admin/login.php.

CVE-2021-33655
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 1 PoC

When sending malicous data to kernel by ioctl cmd FBIOPUT_VSCREENINFO,kernel will write memory out of bounds.

CVE-2021-30175
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
60.5%
2021 0 PoCs

ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.

CVE-2021-25065
Smash Balloon Social Post Feed Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.1%
2021 CWE-79 1 PoC

The Smash Balloon Social Post Feed WordPress plugin before 4.1.1 was affected by a reflected XSS in custom-facebook-feed in cff-top admin page.

CVE-2021-32918
Software Genérico General
N/A
UNKNOWN
EPSS
2.9%
2021 2 PoCs

An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.

CVE-2021-25768
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.

CVE-2021-40323
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
93.2%
2021 0 PoCs

Cobbler before 3.3.0 allows log poisoning, and resultant Remote Code Execution, via an XMLRPC method that logs to the logfile for template injection.

CVE-2021-21110
Chrome General
N/A
UNKNOWN
EPSS
23.1%
2021 1 PoC

Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVE-2021-24725
Comment Link Remove and Other Comment Tools Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 2 PoCs

The Comment Link Remove and Other Comment Tools WordPress plugin before 2.1.6 does not have CSRF check in its 'Delete comments easily', which could allow attackers to make logged in admin delete arbitrary comments

CVE-2021-45910
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in gif2apng 1.9. There is a heap-based buffer overflow within the main function. It allows an attacker to write data outside of the allocated buffer. The attacker has control over a part of the address that data is written to, control over the written data, and (to some extent) control over the amount of data that is written.

CVE-2021-24628
Wow Forms – create any form with custom style Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-89 2 PoCs

The Wow Forms WordPress plugin through 3.1.3 does not sanitise or escape a 'did' GET parameter before using it in a SQL statement, when deleting a form in the admin dashboard, leading to an authenticated SQL injection

CVE-2021-27185
Software Genérico General
N/A
UNKNOWN
EPSS
19.3%
2021 1 PoC

The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.