7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-32256
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

CVE-2021-24152
Popup Builder – Responsive WordPress Pop up – Subscription & Newsletter Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The "All Subscribers" setting page of Popup Builder was vulnerable to reflected Cross-Site Scripting.

CVE-2021-44648
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.

CVE-2021-28970
Software Genérico Database
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. According to the vendor, the issue is fixed in 9.0.3.

CVE-2021-24937
Asset CleanUp: Page Speed Booster Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Asset CleanUp: Page Speed Booster WordPress plugin before 1.3.8.5 does not escape the wpacu_selected_sub_tab_area parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting issue

CVE-2021-0313
Android General
N/A
UNKNOWN
EPSS
3.7%
2021 1 PoC

In isWordBreakAfter of LayoutUtils.cpp, there is a possible way to slow or crash a TextView due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-9, Android-10, Android-11, Android-8.0, Android-8.1; Android ID: A-170968514.

CVE-2021-27919
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.

CVE-2021-44037
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.

CVE-2021-42644
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.

CVE-2021-43545
Thunderbird Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVE-2021-46310
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered IW44Image.cpp in djvulibre 3.5.28 in allows attackers to cause a denial of service via divide by zero.

CVE-2021-37161
Software Genérico General
N/A
UNKNOWN
EPSS
7.6%
2021 2 PoCs

A buffer overflow issue was discovered in the HMI3 Control Panel contained within the Swisslog Healthcare Nexus Panel, operated by released versions of software before Nexus Software 7.2.5.7. A buffer overflow allows an attacker to overwrite an internal queue data structure and can lead to remote code execution.

CVE-2021-44444
JT Utilities General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-125 1 PoC

A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing specially crafted JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-15052)

CVE-2021-42670
Software Genérico Web Database
N/A
UNKNOWN
EPSS
58.0%
2021 3 PoCs

A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.

CVE-2021-46703
Software Genérico General
N/A
UNKNOWN
EPSS
1.4%
2021 1 PoC

In the IsolatedRazorEngine component of Antaris RazorEngine through 4.5.1-alpha001, an attacker can execute arbitrary .NET code in a sandboxed environment (if users can externally control template contents). NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-46078
Software Genérico Web
N/A
UNKNOWN
EPSS
1.8%
2021 1 PoC

An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to a Stored Cross-Site Scripting vulnerability.

CVE-2021-41794
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer overflow. The attacker can send a PFCP Session Establishment Request with "internet" as the PDI Network Instance. The first character is interpreted as a length value to be used in a memcpy call. The destination buffer is only 100 bytes long on the stack. Then, 'i' gets interpreted as 105 bytes to copy from the source buffer to the destination buffer.

CVE-2021-37389
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Chamilo 1.11.14 allows stored XSS via main/install/index.php and main/install/ajax.php through the port parameter.

CVE-2021-24150
Like Button Rating ♥ LikeBtn Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
46.3%
2021 CWE-918 1 PoC

The LikeBtn WordPress Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.32 was vulnerable to Unauthenticated Full-Read Server-Side Request Forgery (SSRF).

CVE-2021-44502
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, an attacker can control the size of a memset that occurs in calls to util_format in sr_unix/util_output.c.