7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-24605
Custom Post View Generator Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue

CVE-2021-32256
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

CVE-2021-25761
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible.

CVE-2021-29266
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_ctx has an invalid value upon re-opening a character device, aka CID-f6bbf0010ba0.

CVE-2021-0513
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In deleteNotificationChannel and related functions of NotificationManagerService.java, there is a possible permission bypass due to improper state validation. This could lead to local escalation of privilege via hidden services with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.1Android ID: A-156090809

CVE-2021-31324
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
80.0%
2021 1 PoC

The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.

CVE-2021-26549
Software Genérico Web
N/A
UNKNOWN
EPSS
1.4%
2021 3 PoCs

An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in a user's browser session in context of an affected site.

CVE-2021-44037
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

CVE-2021-42644
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.

CVE-2021-25407
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-787 2 PoCs

A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

CVE-2021-44967
Software Genérico Web
N/A
UNKNOWN
EPSS
75.9%
2021 4 PoCs

A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install plugins function, which could let a remote malicious user upload an arbitrary PHP code file. NOTE: the Supplier's position is that plugins intentionally can contain arbitrary PHP code, and can only be installed by a superadmin, and therefore the security model is not violated by this finding.

CVE-2021-24613
Post Views Counter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed

CVE-2021-26393
AMD Radeon RX 5000 Series & PRO W5000 Series General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.

CVE-2021-26596
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.

CVE-2021-26310
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.

CVE-2021-47536
Linux General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix wrong list_del in smc_lgr_cleanup_early smc_lgr_cleanup_early() meant to delete the link group from the link group list, but it deleted the list head by mistake. This may cause memory corruption since we didn't remove the real link group from the list and later memseted the link group structure. We got a list corruption panic when testing: [  231.277259] list_del corruption. prev->next should be ffff8881398a8000, but was 0000000000000000 [  231.278222] ------------[ cut here ]------------ [  231.278726] kernel

CVE-2021-24283
Accordion Web
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.

CVE-2021-24464
YouTube Embed, Playlist and Popup by WpDevArt Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The YouTube Embed, Playlist and Popup by WpDevArt WordPress plugin before 2.3.9 did not escape, validate or sanitise some of its shortcode options, available to users with a role as low as Contributor, leading to an authenticated Stored Cross-Site Scripting issue.

CVE-2021-25760
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible.

CVE-2021-26338
2nd Gen AMD EPYC™ General
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-284 1 PoC

Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.