7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26362
Ryzen™ Series General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.

CVE-2021-24670
CoolClock – a Javascript Analog Clock Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The CoolClock WordPress plugin before 4.3.5 does not escape some shortcode attributes, allowing users with a role as low as Contributor toperform Stored Cross-Site Scripting attacks

CVE-2021-44033
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.

CVE-2021-38490
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Altova MobileTogether Server before 7.3 SP1 allows XML exponential entity expansion, a different vulnerability than CVE-2021-37425.

CVE-2021-37551
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.

CVE-2021-4057
Chrome Web
N/A
UNKNOWN
EPSS
3.0%
2021 1 PoC

Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-41738
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2021 2 PoCs

ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.

CVE-2021-40159
Inventor General
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with other vulnerabilities may lead to code execution through maliciously crafted JT files in the context of the current process.

CVE-2021-24462
Photo Gallery by Ays – Responsive Image Gallery Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The get_gallery_categories() and get_galleries() functions in the Photo Gallery by Ays – Responsive Image Gallery WordPress plugin before 4.4.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard

CVE-2021-25085
WOOF – Products Filter for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.2%
2021 CWE-79 1 PoC

The WOOF WordPress plugin before 1.2.6.3 does not sanitise and escape the woof_redraw_elements before outputing back in an admin page, leading to a Reflected Cross-Site Scripting

CVE-2021-4002
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-459 4 PoCs

A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.

CVE-2021-25162
Aruba Instant Access Points General
N/A
UNKNOWN
EPSS
35.9%
2021 3 PoCs

A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant 8.3.x: 8.3.0.14 and below; Aruba Instant 8.5.x: 8.5.0.11 and below; Aruba Instant 8.6.x: 8.6.0.7 and below; Aruba Instant 8.7.x: 8.7.1.1 and below. Aruba has released patches for Aruba Instant that address this security vulnerability.

CVE-2021-31857
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

In Zoho ManageEngine Password Manager Pro before 11.1 build 11104, attackers are able to retrieve credentials via a browser extension for non-website resource types.

CVE-2021-43462
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.

CVE-2021-27544
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote attackers to execute arbitrary code by injecting arbitrary HTML into the "sername" parameter.

CVE-2021-24587
Splash Header Web Windows
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-79 1 PoC

The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.

CVE-2021-20067
Racom MIDGE Firmware General
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authentication.

CVE-2021-24940
ووکامرس فارسی Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-79 1 PoC

The Persian Woocommerce WordPress plugin through 5.8.0 does not escape the s parameter before outputting it back in an attribute in the admin dashboard, which could lead to a Reflected Cross-Site Scripting issue

CVE-2021-41441
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, for the router to reboot.

CVE-2021-43000
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Amzetta zPortal Windows zClient is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal Windows zClient <= v3.2.8180.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.