7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26690
Apache HTTP Server Web
N/A
UNKNOWN
EPSS
67.4%
2021 5 PoCs

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Cookie header handled by mod_session can cause a NULL pointer dereference and crash, leading to a possible Denial Of Service

CVE-2021-38571
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and CNVD-C-2021-68502.

CVE-2021-25424
Tizen wearable devices General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-287 1 PoC

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

CVE-2021-41426
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Beeline Smart box 2.0.38 is vulnerable to Cross Site Request Forgery (CSRF) via mgt_end_user.htm.

CVE-2021-28093
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due to use of Adler32.

CVE-2021-35309
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.

CVE-2021-26233
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

FastStone Image Viewer <= 7.5 is affected by a user mode write access violation near NULL at 0x005bdfcb, triggered when a user opens or views a malformed CUR file that is mishandled by FSViewer.exe. Attackers could exploit this issue for a Denial of Service (DoS) or possibly to achieve code execution.

CVE-2021-42635
Software Genérico General
N/A
UNKNOWN
EPSS
23.5%
2021 3 PoCs

PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.

CVE-2021-34805
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.9%
2021 2 PoCs

An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal.

CVE-2021-20270
python-pygments General
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-835 1 PoC

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

CVE-2021-45906
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.

CVE-2021-46453
Software Genérico General
N/A
UNKNOWN
EPSS
4.3%
2021 1 PoC

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list parameter.

CVE-2021-42392
h2 Windows
N/A
UNKNOWN
EPSS
90.6%
2021 CWE-502 3 PoCs

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVE-2021-42688
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-44497
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An issue was discovered in FIS GT.M through V7.0-000 (related to the YottaDB code base). Using crafted input, can cause the bounds of a for loop to be miscalculated, which leads to a use after free condition a pointer is pushed into previously free memory by the loop.

CVE-2021-42979
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

NoMachine Cloud Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Cloud Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-30178
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.

CVE-2021-43183
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.

CVE-2021-34073
Software Genérico Web Database
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.

CVE-2021-25081
Maps Plugin using Google Maps for WordPress – WP Google Map Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-352 1 PoC

The Maps Plugin using Google Maps for WordPress plugin before 1.8.4 does not have CSRF checks in most of its AJAX actions, which could allow attackers to make logged in admins delete arbitrary posts and update the plugin's settings via a CSRF attack