7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26705
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getConnections without authentication, the results of which can be used to generate valid authentication tokens. These tokens can then be used to invoke administrative tasks within the application, such as disclosing password hashes.

CVE-2021-41317
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

XSS Hunter Express before 2021-09-17 does not properly enforce authentication requirements for paths.

CVE-2021-3004
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The _deposit function in the smart contract implementation for Stable Yield Credit (yCREDIT), an Ethereum token, has certain incorrect calculations. An attacker can obtain more yCREDIT tokens than they should.

CVE-2021-20294
binutils General
N/A
UNKNOWN
EPSS
22.7%
2021 CWE-787 1 PoC

A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.

CVE-2021-34170
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2021 1 PoC

Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.

CVE-2021-43439
Software Genérico General
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely

CVE-2021-24736
Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.

CVE-2021-30132
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.

CVE-2021-20150
Trendnet AC2600 TEW-827DRU General ⚡ nuclei
N/A
UNKNOWN
EPSS
56.6%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 improperly discloses information via redirection from the setup wizard. Authentication can be bypassed and a user may view information as Admin by manually browsing to the setup wizard and forcing it to redirect to the desired page.

CVE-2021-24762
Perfect Survey Web Database Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
85.7%
2021 CWE-89 3 PoCs

The Perfect Survey WordPress plugin before 1.5.2 does not validate and escape the question_id GET parameter before using it in a SQL statement in the get_question AJAX action, allowing unauthenticated users to perform SQL injection.

CVE-2021-41728
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.

CVE-2021-24729
Logo Showcase with Slick Slider – Logo Carousel, Logo Slider & Logo Grid Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Logo Showcase with Slick Slider WordPress plugin before 1.2.4 does not sanitise the Grid Settings, which could allow users with a role as low as Author to perform stored Cross-Site Scripting attacks via post metadata of Grid logo showcase.

CVE-2021-31935
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandled in the scheduling view.

CVE-2021-29647
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 2 PoCs

An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.

CVE-2021-24385
FileBird – WordPress Media Library Folders & File Manager Web Database Windows
N/A
UNKNOWN
EPSS
9.0%
2021 CWE-89 1 PoC

The Filebird Plugin 4.7.3 introduced a SQL injection vulnerability as it is making SQL queries without escaping user input data from a HTTP post request. This is a major vulnerability as the user input is not escaped and passed directly to the get_col function and it allows SQL injection. The Rest API endpoint which invokes this function also does not have any required permissions/authentication and can be accessed by an anonymous user.

CVE-2021-0317
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In createOrUpdate of Permission.java and related code, there is possible permission escalation due to a logic error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android; Versions: Android-10, Android-11, Android-8.0, Android-8.1, Android-9; Android ID: A-168319670.

CVE-2021-43195
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.

CVE-2021-24852
MouseWheel Smooth Scroll Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which could allow attackers to make a logged in admin change them via a CSRF attack

CVE-2021-43399
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and some data operations received from a YubiHSM 2 device.

CVE-2021-32459
Trend Micro Home Network Security General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log collection server which could allow an attacker to use a specially crafted network request to lead to arbitrary authentication. An attacker must first obtain the ability to execute high-privileged code on the target device in order to exploit this vulnerability.