7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24326
All 404 Redirect to Homepage Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The tab parameter of the settings page of the All 404 Redirect to Homepage WordPress plugin before 1.21 was vulnerable to an authenticated reflected Cross-Site Scripting (XSS) issue as user input was not properly sanitised before being output in an attribute.

CVE-2021-23924
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

CVE-2021-38584
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

CVE-2021-36981
Software Genérico General
N/A
UNKNOWN
EPSS
16.5%
2021 1 PoC

In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to execute arbitrary code.

CVE-2021-3564
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-415 3 PoCs

A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.

CVE-2021-38704
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
5.0%
2021 1 PoC

Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.

CVE-2021-46424
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
91.5%
2021 1 PoC

Telesquare TLR-2005KSH 1.0.0 is affected by an arbitrary file deletion vulnerability that allows a remote attacker to delete any file, even system internal files, via a DELETE request.

CVE-2021-21992
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service condition on the vCenter Server host.

CVE-2021-42099
Software Genérico General
N/A
UNKNOWN
EPSS
22.4%
2021 1 PoC

Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.

CVE-2021-24696
Simple Download Monitor Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads

CVE-2021-45897
Software Genérico General
N/A
UNKNOWN
EPSS
24.6%
2021 1 PoC

SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.

CVE-2021-28146
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVE-2021-40382
Software Genérico General
N/A
UNKNOWN
EPSS
39.5%
2021 1 PoC

An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.

CVE-2021-32256
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

CVE-2021-25761
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

CVE-2021-29266
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0.

CVE-2021-0513
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-156090809

CVE-2021-44037
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

CVE-2021-42644
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.

CVE-2021-25407
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 2 PoCs

A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.