7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-43325
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a CVE-2021-43326 regression.

CVE-2021-25142
HPE Apollo 70 System General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.

CVE-2021-43463
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.

CVE-2021-34693
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized.

CVE-2021-41594
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by intercepting the API request at the /api/V2/internal/TaskPermissions/CheckTaskAccess endpoint. If the parameters of this request are replaced with empty fields, the attacker achieves access to the precluded functions.

CVE-2021-20076
Tenable.sc General
N/A
UNKNOWN
EPSS
3.4%
2021 1 PoC

Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an authenticated, unprivileged user to perform Remote Code Execution (RCE) on the Tenable.sc server via Hypertext Preprocessor unserialization.

CVE-2021-0507
Android General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

In handle_rc_metamsg_cmd of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-181860042

CVE-2021-25420
Galaxy Watch PlugIn General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-779 1 PoC

Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

CVE-2021-0511
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In Dex2oat of dex2oat.cc, there is a possible way to inject bytecode into an app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-178055795

CVE-2021-24364
Jannah Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
2.0%
2021 CWE-79 1 PoC

The Jannah WordPress theme before 5.4.4 did not properly sanitize the options JSON parameter in its tie_get_user_weather AJAX action before outputting it back in the page, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.

CVE-2021-32014
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xlsx document that is mishandled when read by xlsx.js.

CVE-2021-20156
Trendnet AC2600 TEW-827DRU General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Trendnet AC2600 TEW-827DRU version 2.08B01 contains an improper access control configuration that could allow for a malicious firmware update. It is possible to manually install firmware that may be malicious in nature as there does not appear to be any signature validation done to determine if it is from a known and trusted source. This includes firmware updates that are done via the automated "check for updates" in the admin interface. If an attacker is able to masquerade as the update server, the device will not verify that the firmware updates downloaded are legitimate.

CVE-2021-3456
smart_proxy_salt General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-863 1 PoC

An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy allows foreman clients to execute actions that should be limited to the Foreman Server. This flaw allows an authenticated local attacker to access and delete limited resources and also causes a denial of service on the Foreman server. The highest threat from this vulnerability is to integrity and system availability.

CVE-2021-39291
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVE-2021-43184
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.

CVE-2021-33338
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack 6, exposes the CSRF token in URLs, which allows man-in-the-middle attackers to obtain the token and conduct Cross-Site Request Forgery (CSRF) attacks via the p_auth parameter.

CVE-2021-29983
Firefox General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 91.

CVE-2021-24562
LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress Web Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-639 1 PoC

The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for WordPress plugin before 4.21.2 was affected by an IDOR issue, allowing students to see other student answers and grades

CVE-2021-39692
Android General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-209611539

CVE-2021-24536
Custom Login Redirect Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

The Custom Login Redirect WordPress plugin through 1.0.0 does not have CSRF check in place when saving its settings, and do not sanitise or escape user input before outputting them back in the page, leading to a Stored Cross-Site Scripting issue