7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25764
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.

CVE-2021-34553
Software Genérico General
N/A
UNKNOWN
EPSS
1.1%
2021 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access.

CVE-2021-3287
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
88.5%
2021 1 PoC

Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the deserialization class.

CVE-2021-40903
Software Genérico General
N/A
UNKNOWN
EPSS
11.6%
2021 3 PoCs

A vulnerability in Antminer Monitor 0.50.0 exists because of backdoor or misconfiguration inside a settings file in flask server. Settings file has a predefined secret string, which would be randomly generated, however it is static.

CVE-2021-37165
Software Genérico General
N/A
UNKNOWN
EPSS
5.0%
2021 1 PoC

A buffer overflow issue was discovered in HMI3 Control Panel in Swisslog Healthcare Nexus Panel operated by released versions of software before Nexus Software 7.2.5.7. When a message is sent to the HMI TCP socket, it is forwarded to the hmiProcessMsg function through the pendingQ, and may lead to remote code execution.

CVE-2021-24382
Smart Slider 3 Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Smart Slider 3 Free and pro WordPress plugins before 3.5.0.9 did not sanitise the Project Name before outputting it back in the page, leading to a Stored Cross-Site Scripting issue. By default, only administrator users could access the affected functionality, limiting the exploitability of the vulnerability. However, some WordPress admins may allow lesser privileged users to access the plugin's functionality, in which case, privilege escalation could be performed.

CVE-2021-33816
Software Genérico Web
N/A
UNKNOWN
EPSS
2.6%
2021 3 PoCs

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

CVE-2021-25774
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.

CVE-2021-31321
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

CVE-2021-41821
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Wazuh Manager in Wazuh through 4.1.5 is affected by a remote Integer Underflow vulnerability that might lead to denial of service. A crafted message must be sent from an authenticated agent to the manager.

CVE-2021-27403
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS.

CVE-2021-3111
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.php/dashboard/express/entries/view/ URI.

CVE-2021-41739
Software Genérico Web
N/A
UNKNOWN
EPSS
6.7%
2021 2 PoCs

A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.

CVE-2021-23017
Nginx Web Server, Nginx Plus Web
N/A
UNKNOWN
EPSS
73.2%
2021 CWE-193 11 PoCs

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

CVE-2021-31611
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Bluetooth Classic implementation on Zhuhai Jieli AC690X and AC692X devices does not properly handle an out-of-order LMP Setup procedure that is followed by a malformed LMP packet, allowing attackers in radio range to deadlock a device via a crafted LMP packet. The user needs to manually reboot the device to restore communication.

CVE-2021-26271
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 2 PoCs

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

CVE-2021-39250
Software Genérico Web
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).

CVE-2021-38705
Software Genérico Web
N/A
UNKNOWN
EPSS
1.0%
2021 1 PoC

ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.

CVE-2021-35508
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges via a low-privileged user account. To exploit this, a low-privileged user must change the service configuration or overwrite the binary service.

CVE-2021-3520
lz4 General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-190 3 PoCs

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.