94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3492
Linux kernel General
8.8
HIGH
EPSS
24.4%
2021 CWE-415 2 PoCs

Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory exhaustion) or gain privileges via executing arbitrary code. AKA ZDI-CAN-13562.

CVE-2021-38003
🔥 KEV Chrome General
8.8
HIGH
EPSS
65.7%
2021 2 PoCs

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-21843
GPAC General
8.8
HIGH
EPSS
0.3%
2021 CWE-680 2 PoCs

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. After validating the number of ranges, at [41] the library will multiply the count by the size of the GF_SubsegmentRangeInfo structure. On a 32-bit platform, this multiplication can result in an integer overflow causing the space of the array being allocated to be less than expe

CVE-2021-47848
Aplikasi-Biro-Travel Database
8.8
HIGH
EPSS
0.0%
2021 CWE-89 1 PoC

Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative access.

CVE-2021-40905
Software Genérico General
8.8
HIGH
EPSS
4.9%
2021 1 PoC

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner

CVE-2021-27661
Facility Explorer SNC Series Supervisory Controllers (F4-SNC) General
8.8
HIGH
EPSS
0.2%
2021 CWE-269 1 PoC

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.

CVE-2021-4349
Process Steps Template Designer Web Windows
8.8
HIGH
EPSS
0.4%
2021 CWE-352 1 PoC

The Process Steps Template Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.1. This makes it possible for unauthenticated attackers to conduct unspecified attacks via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2021-44142
Samba Windows
8.8
HIGH
EPSS
35.7%
2021 CWE-125 4 PoCs

The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.

CVE-2021-31181
Microsoft SharePoint Enterprise Server 2016 Windows
8.8
HIGH
EPSS
40.7%
2021 1 PoC

Microsoft SharePoint Remote Code Execution Vulnerability

CVE-2021-40444
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
94.3%
2021 44 PoCs

<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.</p> <p>An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who oper

CVE-2021-38617
Software Genérico General
8.8
HIGH
EPSS
0.9%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/ user creation endpoint allows a standard user to create a super user account with a defined password. This directly leads to privilege escalation.

CVE-2021-3855
Liman Central Management System Web
8.8
HIGH
EPSS
1.5%
2021 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection.This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462.

CVE-2021-39613
Software Genérico General
8.8
HIGH
EPSS
1.3%
2021 2 PoCs

D-Link DVG-3104MS version 1.0.2.0.3, 1.0.2.0.4, and 1.0.2.0.4E contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file. As weak passwords have been used, the plaintext passwords can be recovered from the hash values. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-27660
C-CURE 9000 Windows
8.8
HIGH
EPSS
1.2%
2021 CWE-20 1 PoC

An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

CVE-2021-21789
Iobit General
8.8
HIGH
EPSS
0.1%
2021 CWE-782 1 PoC

A privilege escalation vulnerability exists in the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O write requests. During IOCTL 0x9c40a0e0, the first dword passed in the input buffer is the device port to write to and the dword at offset 4 is the value to write via the OUT instruction. A local attacker can send a malicious IRP to trigger this vulnerability.

CVE-2021-3785
yourls/yourls Web
8.8
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

yourls is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-39172
Cachet General
8.8
HIGH
EPSS
55.5%
2021 CWE-93 2 PoCs

Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges (User or Admin), can exploit a new line injection in the configuration edition feature (e.g. mail settings) and gain arbitrary code execution on the server. This issue was addressed in version 2.5.1 by improving `UpdateConfigCommandHandler` and preventing the use of new lines characters in new configuration values. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.

CVE-2021-31599
Software Genérico General
8.8
HIGH
EPSS
0.9%
2021 1 PoC

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. A reports (.prpt) file allows the inclusion of BeanShell scripts to ease the production of complex reports. An authenticated user can run arbitrary code.

CVE-2021-39173
Cachet General
8.8
HIGH
EPSS
3.7%
2021 CWE-704 1 PoC

Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges (User or Admin), can trick Cachet and install the instance again, leading to arbitrary code execution on the server. This issue was addressed in version 2.5.1 by improving the middleware `ReadyForUse`, which now performs a stricter validation of the instance name. As a workaround, only allow trusted source IP addresses to access to the administration dashboard.