7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-28271
Software Genérico General
N/A
UNKNOWN
EPSS
2.4%
2021 3 PoCs

Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group.

CVE-2021-0390
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In various methods of WifiNetworkSuggestionsManager.java, there is a possible modification of suggested networks due to a missing permission check. This could lead to local escalation of privilege by a background user on the same device with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-174749461

CVE-2021-38160
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vulnerability in any existing use case; the length validation was added solely for robustness in the face of anomalous host OS behavior

CVE-2021-41646
Software Genérico Web
N/A
UNKNOWN
EPSS
8.9%
2021 3 PoCs

Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..

CVE-2021-24899
Media Tags Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Media-Tags WordPress plugin through 3.2.0.2 does not sanitise and escape any of its Labels settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_htnl capability is disallowed.

CVE-2021-3653
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-862 1 PoC

A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "int_ctl" field, this issue could allow a malicious L1 to enable AVIC support (Advanced Virtual Interrupt Controller) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. This flaw affects Linux kern

CVE-2021-30490
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.

CVE-2021-26723
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
64.1%
2021 2 PoCs

Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.

CVE-2021-36231
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attackers to execute operating system commands by crafting serialized objects.

CVE-2021-42559
Software Genérico Web
N/A
UNKNOWN
EPSS
4.0%
2021 2 PoCs

An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary commands that will execute when the server is restarted.

CVE-2021-45888
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in PONTON X/P Messenger before 3.11.2. The navigation tree that is shown on the left side of every page of the web application is vulnerable to XSS: it allows injection of JavaScript into its nodes. Creating such nodes is only possible for users who have the role Configuration Administrator or Administrator.

CVE-2021-22057
VMware Workspace ONE Access General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify.

CVE-2021-24779
WP Debugging Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The WP Debugging WordPress plugin before 2.11.0 has its update_settings() function hooked to admin_init and is missing any authorisation and CSRF checks, as a result, the settings can be updated by unauthenticated users.

CVE-2021-24220
Rise by Thrive Themes Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
63.8%
2021 CWE-434 2 PoCs

Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes WordPress theme before 2.0.0, Voice WordPress theme before 2.0.0, Performag by Thrive Themes WordPress theme before 2.0.0, Pressive by Thrive Themes WordPress theme before 2.0.0, Storied by Thrive Themes WordPress theme before 2.0.0 register a REST API endpoint to compress images using th

CVE-2021-25439
Samsung Members General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-284 1 PoC

Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.

CVE-2021-25417
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-285 1 PoC

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

CVE-2021-33561
Software Genérico Web
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

A stored cross-site scripting (XSS) vulnerability in Shopizer before 2.17.0 allows remote attackers to inject arbitrary web script or HTML via customer_name in various forms of store administration. It is saved in the database. The code is executed for any user of store administration when information is fetched from the backend, e.g., in admin/customers/list.html.

CVE-2021-40091
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

An SSRF issue was discovered in SquaredUp for SCOM 5.2.1.6654.

CVE-2021-24159
Contact Form 7 Style Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

Due to the lack of sanitization and lack of nonce protection on the custom CSS feature, an attacker could craft a request to inject malicious JavaScript on a site using the Contact Form 7 Style WordPress plugin through 3.1.9. If an attacker successfully tricked a site’s administrator into clicking a link or attachment, then the request could be sent and the CSS settings would be successfully updated to include malicious JavaScript.

CVE-2021-46754
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.