7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25074
WebP Converter for Media – Convert WebP and AVIF & Optimize Images Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-601 1 PoC

The WebP Converter for Media WordPress plugin before 4.0.3 contains a file (passthru.php) which does not validate the src parameter before redirecting the user to it, leading to an Open Redirect issue

CVE-2021-27971
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.

CVE-2021-26372
EPYC™ Processors General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

CVE-2021-31319
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-26797
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administrator through an open Telnet service.

CVE-2021-39674
Android General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In btm_sec_connected and btm_sec_disconnected of btm_sec.cc file , there is a possible use after free. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-201083442

CVE-2021-32160
Software Genérico Web
N/A
UNKNOWN
EPSS
8.1%
2021 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Webmin 1.973 through the Add Users feature.

CVE-2021-21993
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

The vCenter Server contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in vCenter Server Content Library. An authorised user with access to content library may exploit this issue by sending a POST request to vCenter Server leading to information disclosure.

CVE-2021-20700
CLUSTERPRO X Windows
N/A
UNKNOWN
EPSS
1.6%
2021 1 PoC

Buffer overflow vulnerability in the Disk Agent CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote code execution via a network.

CVE-2021-24288
Newsletter via SMTP, Sendinblue, Sendgrid, Mailgun - AcyMailing SMTP Newsletter General ⚡ nuclei
N/A
UNKNOWN
EPSS
4.4%
2021 CWE-601 1 PoC

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

CVE-2021-33515
Software Genérico General
N/A
UNKNOWN
EPSS
5.9%
2021 1 PoC

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.

CVE-2021-24831
Tab – Accordion, FAQ Web Windows
N/A
UNKNOWN
EPSS
0.9%
2021 CWE-862 1 PoC

All AJAX actions of the Tab WordPress plugin before 1.3.2 are available to both unauthenticated and authenticated users, allowing unauthenticated attackers to modify various data in the plugin, such as add/edit/delete arbitrary tabs.

CVE-2021-25264
Intercept X for MacOS General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.

CVE-2021-3287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.5%
2021 1 PoC

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

CVE-2021-40903
Software Genérico General
N/A
UNKNOWN
EPSS
11.6%
2021 3 PoCs

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

CVE-2021-37165
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2021 1 PoC

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.

CVE-2021-24382
Smart Slider 3 Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.

CVE-2021-33816
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 3 PoCs

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

CVE-2021-25774
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.

CVE-2021-31321
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.