7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25399
Smart Manager General
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-285 1 PoC

Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

CVE-2021-43396
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 3 PoCs

In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.

CVE-2021-20142
Gryphon Tower router Networking
N/A
UNKNOWN
EPSS
7.8%
2021 1 PoC

An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute commands as root on the device by sending a specially crafted malicious packet to the controller_server service on port 9999.

CVE-2021-42697
Software Genérico Web
N/A
UNKNOWN
EPSS
75.5%
2021 2 PoCs

Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing HTTP headers, which allows a remote attacker to conduct a Denial of Service attack by sending a User-Agent header with deeply nested comments.

CVE-2021-20137
Gryphon Tower router Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
11.5%
2021 1 PoC

A reflected cross-site scripting vulnerability exists in the url parameter of the /cgi-bin/luci/site_access/ page on the Gryphon Tower router's web interface. An attacker could exploit this issue by tricking a user into following a specially crafted link, granting the attacker javascript execution in the context of the victim's browser.

CVE-2021-34815
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter.

CVE-2021-22045
VMware ESXi, VMware Workstation and VMware Fusion General
N/A
UNKNOWN
EPSS
0.4%
2021 2 PoCs

VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and VMware Fusion (12.2.0) contains a heap-overflow vulnerability in CD-ROM device emulation. A malicious actor with access to a virtual machine with CD-ROM device emulation may be able to exploit this vulnerability in conjunction with other issues to execute code on the hypervisor from a virtual machine.

CVE-2021-36580
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
10.0%
2021 2 PoCs

Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.

CVE-2021-41987
Software Genérico Networking
N/A
UNKNOWN
EPSS
49.6%
2021 1 PoC

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.

CVE-2021-42223
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2021 1 PoC

Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.

CVE-2021-36706
Software Genérico General
N/A
UNKNOWN
EPSS
13.1%
2021 1 PoC

In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter value of sysCMD contains a trivial command injection where the value of the command parameter is passed directly to system.

CVE-2021-28142
Software Genérico General
N/A
UNKNOWN
EPSS
4.0%
2021 1 PoC

CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."

CVE-2021-29267
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 1 PoC

Sherlock SherlockIM through 2021-03-29 allows Cross Site Scripting (XSS) by leveraging the api/Files/Attachment URI to attack help-desk staff via the chatbot feature.

CVE-2021-1061
NVIDIA Virtual GPU Manager General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-25276
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a valid profile file to this directory. For example, if this profile sets up a user with a C:\ home directory, then the attacker obtains access to read or replace arbitrary files with LocalSystem privileges.

CVE-2021-43438
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field

CVE-2021-24136
Testimonials Widget Web Windows
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the Testimonials Widget WordPress plugin, versions before 4.0.0, lead to multiple Cross-Site Scripting vulnerabilities, allowing remote attackers to inject arbitrary JavaScript code or HTML via the below parameters: - Author - Job Title - Location - Company - Email - URL

CVE-2021-25306
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers to force a device reboot by sending relatively long AT commands.

CVE-2021-24941
Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The Popups, Welcome Bar, Optins and Lead Generation Plugin WordPress plugin before 2.0.5 does not sanitise and escape the message_id parameter of the get_message_action_row AJAX action before outputting it back in an attribute, leading to a reflected Cross-Site Scripting issue

CVE-2021-3578
isync General
N/A
UNKNOWN
EPSS
1.9%
2021 CWE-704 1 PoC

A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly exploited for remote code execution on the client.