7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3487
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-20265
kernel General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-400 2 PoCs

A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.

CVE-2021-24856
Shared Files – Easy Download Manager and File Sharing Plugin with Frontend File Upload Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-37589
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
77.7%
2021 2 PoCs

Virtua Cobranca before 12R allows SQL Injection on the login page.

CVE-2021-20114
TCExam General ⚡ nuclei
N/A
UNKNOWN
EPSS
53.9%
2021 0 PoCs

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.

CVE-2021-24839
SupportCandy – Helpdesk & Support Ticket System Web Windows
N/A
UNKNOWN
EPSS
1.0%
2021 CWE-862 1 PoC

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be affected as well.

CVE-2021-26787
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion) via the Time-off parameter.

CVE-2021-22008
VMware vCenter Server, VMware Cloud Foundation Web Cloud
N/A
UNKNOWN
EPSS
0.7%
2021 1 PoC

The vCenter Server contains an information disclosure vulnerability in VAPI (vCenter API) service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by sending a specially crafted json-rpc message to gain access to sensitive information.

CVE-2021-26576
HPE Apollo 70 System Networking
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.

CVE-2021-29394
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

CVE-2021-33208
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2021 1 PoC

The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.

CVE-2021-46889
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

The 10Web Photo Gallery plugin through 1.5.69 for WordPress allows XSS via theme_id for bwg_frontend_data. NOTE: other parameters are covered by CVE-2021-24291, CVE-2021-25041, and CVE-2021-31693.

CVE-2021-20705
CLUSTERPRO X Windows
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows attacker to remote file upload via network.

CVE-2021-3124
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to inject arbitrary code via the vars[0][name] field.

CVE-2021-30504
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 2 PoCs

In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.

CVE-2021-24337
Video Embed Web Database Windows
N/A
UNKNOWN
EPSS
0.6%
2021 CWE-89 2 PoCs

The id GET parameter of one of the Video Embed WordPress plugin through 1.0's page (available via forced browsing) is not sanitised, validated or escaped before being used in a SQL statement, allowing low privilege users, such as subscribers, to perform SQL injection.

CVE-2021-42646
Software Genérico Web
N/A
UNKNOWN
EPSS
1.3%
2021 2 PoCs

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.0, 3.1.0, 3.2.0, and 4.0.0; and WSO2 IS as Key Manager 5.7.0, 5.9.0, and 5.10.0; and WSO2 Identity Server 5.7.0, 5.8.0, 5.9.0, 5.10.0, and 5.11.0. Allows attackers to gain read access to sensitive information or cause a denial of service via crafted GET requests.

CVE-2021-36224
Software Genérico Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

Western Digital My Cloud devices before OS5 have a nobody account with a blank password.

CVE-2021-46454
Software Genérico General
N/A
UNKNOWN
EPSS
28.6%
2021 1 PoC

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnerability allows attackers to execute arbitrary commands via the ApCliKeyStr parameter.

CVE-2021-33205
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2021 1 PoC

Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library and stealing user credentials.