7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43546
Thunderbird General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-3739
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-476 2 PoCs

A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.

CVE-2021-34415
Zoom On-Premise Meeting Connector Controller General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not verify the cnt field sent in incoming network packets, which leads to exhaustion of resources and system crash.

CVE-2021-24965
Five Star Restaurant Reservations – WordPress Booking Plugin Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Five Star Restaurant Reservations WordPress plugin before 2.4.8 does not have capability and CSRF checks in the rtb_welcome_set_schedule AJAX action, allowing any authenticated users to call it. Due to the lack of sanitisation and escaping, users with a role as low as subscriber could perform Cross-Site Scripting attacks against logged in admins

CVE-2021-26351
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.

CVE-2021-28377
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
52.6%
2021 1 PoC

ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.

CVE-2021-26832
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Cross Site Scripting (XSS) in the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on behalf of the victim by sending a malicious URL or directing the victim to a malicious site.

CVE-2021-25067
Landing Page Builder – Lead Page – Optin Page – Squeeze Page – WordPress Landing Pages Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.1%
2021 CWE-79 1 PoC

The Landing Page Builder WordPress plugin before 1.4.9.6 was affected by a reflected XSS in page-builder-add on the ulpb_post admin page.

CVE-2021-41526
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.

CVE-2021-24766
404 to 301 – Redirect, Log and Notify 404 Errors Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The 404 to 301 – Redirect, Log and Notify 404 Errors WordPress plugin before 3.0.9 does not have CSRF check in place when cleaning the logs, which could allow attacker to make a logged in admin delete all of them via a CSRF attack

CVE-2021-24192
Tree Sitemap (Pages, Posts & Categories list) Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-285 1 PoC

Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.

CVE-2021-3715
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-416 1 PoC

A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

CVE-2021-41324
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete).

CVE-2021-24142
301 Redirects - Easy Redirect Manager Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections.

CVE-2021-24529
Grid Gallery – Photo Image Grid Gallery Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 1 PoC

The Grid Gallery – Photo Image Grid Gallery WordPress plugin before 1.2.5 does not properly sanitize the title field for image galleries when adding them via the admin dashboard, resulting in an authenticated Stored Cross-Site Scripting vulnerability.

CVE-2021-42063
SAP Knowledge Warehouse Web ⚡ nuclei
N/A
UNKNOWN
EPSS
40.8%
2021 3 PoCs

A security vulnerability has been discovered in the SAP Knowledge Warehouse - versions 7.30, 7.31, 7.40, 7.50. The usage of one SAP KW component within a Web browser enables unauthorized attackers to conduct XSS attacks, which might lead to disclose sensitive data.

CVE-2021-35943
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Couchbase Server 6.5.x and 6.6.x through 6.6.2 has Incorrect Access Control. Externally managed users are not prevented from using an empty password, per RFC4513.

CVE-2021-24539
Coming Soon, Under Construction & Maintenance Mode By Dazzler Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Coming Soon, Under Construction & Maintenance Mode By Dazzler WordPress plugin before 1.6.7 does not sanitise or escape its description setting when outputting it in the frontend when the Coming Soon mode is enabled, even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVE-2021-42912
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows the attacker, once logged in, to send commands to the operating system as the root user via the ping diagnostic tool, bypassing the IP address field, and concatenating OS commands with a semicolon.

CVE-2021-25832
Software Genérico General
N/A
UNKNOWN
EPSS
7.0%
2021 1 PoC

A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v6.0.0. Using this vulnerability, an attacker is able to gain remote code executions on DocumentServer.