7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-28663
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
2.7%
2021 3 PoCs

The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.

CVE-2021-4080
crater-invoice/crater General
8.8
HIGH
EPSS
0.4%
2021 CWE-434 1 PoC

crater is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-38617
Software Genérico General
8.8
HIGH
EPSS
0.9%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation.

CVE-2021-47846
Digital Crime Report Management System Database
8.8
HIGH
EPSS
0.1%
2021 CWE-89 1 PoC

Digital Crime Report Management System 1.0 contains a critical SQL injection vulnerability affecting multiple login pages that allows unauthenticated attackers to bypass authentication. Attackers can exploit the vulnerability by sending crafted SQL injection payloads in email and password parameters across police, incharge, user, and HQ login endpoints.

CVE-2021-21899
LibreCAD General
8.8
HIGH
EPSS
0.4%
2021 CWE-119 1 PoC

A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-38819
Software Genérico Database
8.8
HIGH
EPSS
0.7%
2021 2 PoCs

A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.

CVE-2021-4349
Process Steps Template Designer Web Windows
8.8
HIGH
EPSS
0.4%
2021 CWE-352 1 PoC

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-28830
TIBCO Enterprise Runtime for R - Server Edition Cloud Windows
8.8
HIGH
EPSS
0.0%
2021 1 PoC

The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO Spotfire Statistics Services, TIBCO Spotfire Statistics Services, and TIBCO Spotfire Statistics Services contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating sy

CVE-2021-21551
🔥 KEV dbutil General
8.8
HIGH
EPSS
64.4%
2021 CWE-782 12 PoCs

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

CVE-2021-21843
GPAC General
8.8
HIGH
EPSS
0.3%
2021 CWE-680 2 PoCs

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. After validating the number of ranges, at [41] the library will multiply the count by the size of the GF_SubsegmentRangeInfo structure. On a 32-bit platform, this multiplication can result in an integer overflow causing the space of the array being allocated to be less than expe

CVE-2021-28822
TIBCO Enterprise Message Service Web Windows
8.8
HIGH
EPSS
0.1%
2021 1 PoC

The Enterprise Message Service Server (tibemsd), Enterprise Message Service Central Administration (tibemsca), Enterprise Message Service JSON configuration generator (tibemsconf2json), and Enterprise Message Service C API components of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contain a vulnerability that theoretically allows a low privileged attacker with local access on the Windows operating system to insert malicious software. The affected component can be abused to

CVE-2021-20039
SonicWall SMA100 Web Networking
8.8
HIGH
EPSS
82.5%
2021 CWE-78 2 PoCs

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.

CVE-2021-31837
McAfee GetSusp General
8.8
HIGH
EPSS
0.1%
2021 CWE-787 1 PoC

Memory corruption vulnerability in the driver file component in McAfee GetSusp prior to 4.0.0 could allow a program being investigated on the local machine to trigger a buffer overflow in GetSusp, leading to the execution of arbitrary code, potentially triggering a BSOD.

CVE-2021-3492
Linux kernel General
8.8
HIGH
EPSS
24.4%
2021 CWE-415 2 PoCs

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

CVE-2021-25994
userfrosting General
8.8
HIGH
EPSS
1.8%
2021 CWE-74 1 PoC

In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.

CVE-2021-25682
apport General
8.8
HIGH
EPSS
0.1%
2021 CWE-20 1 PoC

It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

CVE-2021-21834
GPAC Project General
8.8
HIGH
EPSS
0.2%
2021 CWE-680 1 PoC

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input when decoding the atom for the “co64” FOURCC can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

CVE-2021-27251
R7800 General
8.8
HIGH
EPSS
0.3%
2021 CWE-319 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR Nighthawk R7800. Authentication is not required to exploit this vulnerability The specific flaw exists within handling of firmware updates. The issue results from a fallback to a insecure protocol to deliver updates. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12308.

CVE-2021-21910
Advantech Windows
8.8
HIGH
EPSS
0.0%
2021 CWE-276 1 PoC

A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-25297
🔥 KEV Software Genérico Web ⚡ nuclei
8.8
HIGH
EPSS
81.9%
2021 3 PoCs

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.