7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43194
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, user enumeration was possible.

CVE-2021-28950
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.

CVE-2021-45025
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to Cleartext Storage of Sensitive Information in a Cookie.

CVE-2021-29156
Software Genérico Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
88.7%
2021 2 PoCs

ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacker can perform character-by-character retrieval of password hashes, or retrieve a session token or a private key.

CVE-2021-24790
Contact Form Advanced Database Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-862 1 PoC

The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.

CVE-2021-27224
Software Genérico General
N/A
UNKNOWN
EPSS
6.3%
2021 2 PoCs

The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012ec6, which might allow remote attackers to execute arbitrary code.

CVE-2021-31249
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
90.0%
2021 1 PoC

A CRLF injection vulnerability was found on BF-430, BF-431, and BF-450M TCP/IP Converter devices from CHIYU Technology Inc due to a lack of validation on the parameter redirect= available on multiple CGI components.

CVE-2021-25330
Samsung Mobile Devices General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-20227
sqlite Database
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-416 3 PoCs

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

CVE-2021-42008
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 5 PoCs

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

CVE-2021-0315
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 3 PoCs

In onCreate of GrantCredentialsPermissionActivity.java, there is a possible way to convince the user to grant an app access to an account due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-8.1, Android-9, Android-10, Android-11, Android-8.0; Android ID: A-169763814.

CVE-2021-44260
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2021 0 PoCs

A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6-20180418, which can allow a remote attacker to access this page without any authentication. When processed, it exposes some key information of the manager of router.

CVE-2021-24752
Essential Widgets Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-284 1 PoC

Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, which could allow any authenticated users, such as Subscriber to change the Essential Widgets WordPress plugin before 1.9, To Top WordPress plugin before 2.3, Header Enhancement WordPress plugin before 1.5, Generate Child Theme WordPress plugin before 1.6, Essential Content Types WordPress plugin before 1.9, Catch Web Tools WordPress plugin before 2.7, Catch Under Construction WordPress plugin before 1.4, Catch Themes Demo Import WordPress plugin before 1.6, Catch Sticky Menu W

CVE-2021-35391
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary code via a crafted URL.

CVE-2021-26705
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.

CVE-2021-3004
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

CVE-2021-20294
binutils General
N/A
UNKNOWN
EPSS
22.7%
2021 CWE-787 1 PoC

A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.

CVE-2021-34170
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2021 1 PoC

Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.

CVE-2021-43439
Software Genérico General
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

CVE-2021-30132
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.