7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-27193
Software Genérico Web
N/A
UNKNOWN
EPSS
1.2%
2021 1 PoC

Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.

CVE-2021-29387
Software Genérico Web
N/A
UNKNOWN
EPSS
0.2%
2021 2 PoCs

Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.

CVE-2021-22018
VMware vCenter Server, VMware Cloud Foundation Cloud
N/A
UNKNOWN
EPSS
0.4%
2021 1 PoC

The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A malicious actor with network access to port 9087 on vCenter Server may exploit this issue to delete non critical files.

CVE-2021-20169
Netgear RAX43 Web
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Netgear RAX43 version 1.0.3.96 does not utilize secure communications to the web interface. By default, all communication to/from the device is sent via HTTP, which causes potentially sensitive information (such as usernames and passwords) to be transmitted in cleartext.

CVE-2021-43006
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2021 1 PoC

AmZetta Amzetta zPortal DVM Tools is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amzetta zPortal DVM Tools <= v3.3.148.148 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.

CVE-2021-47760
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Sin descripción disponible.

CVE-2021-20092
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 General ⚡ nuclei
N/A
UNKNOWN
EPSS
68.8%
2021 1 PoC

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

CVE-2021-3544
QEMU General
N/A
UNKNOWN
EPSS
0.0%
2021 CWE-401 1 PoC

Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and including 6.0. They exist in contrib/vhost-user-gpu/vhost-user-gpu.c and contrib/vhost-user-gpu/virgl.c due to improper release of memory (i.e., free) after effective lifetime.

CVE-2021-24126
Envira Gallery Lite Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

Unvalidated input and lack of output encoding in the Envira Gallery Lite WordPress plugin, versions before 1.8.3.3, did not properly sanitise the images metadata (namely title) before outputting them in the generated gallery, which could lead to privilege escalation.

CVE-2021-46005
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
12.4%
2021 3 PoCs

Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.

CVE-2021-3254
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2021 1 PoC

Asus DSL-N14U-B1 1.1.2.3_805 allows remote attackers to cause a Denial of Service (DoS) via a TCP SYN scan using nmap.

CVE-2021-24841
Helpful Web Windows
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-79 2 PoCs

The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVE-2021-25830
Software Genérico General
N/A
UNKNOWN
EPSS
6.1%
2021 1 PoC

A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacker must request the conversion of the crafted file from DOCT into DOCX format. Using the chain of two other bugs related to improper string handling, an attacker can achieve remote code execution on DocumentServer.

CVE-2021-24370
Fancy Product Designer Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
79.8%
2021 CWE-434 4 PoCs

The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.

CVE-2021-30047
Software Genérico General
N/A
UNKNOWN
EPSS
33.9%
2021 1 PoC

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

CVE-2021-24506
Slider Hero with Animation, Video Background & Intro Maker Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2021 CWE-89 1 PoC

The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using it in a SQL statement, allowing users with a role as low as Contributor to perform SQL injection.

CVE-2021-40961
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.3%
2021 3 PoCs

CMS Made Simple <=2.2.15 is affected by SQL injection in modules/News/function.admin_articlestab.php. The $sortby variable is concatenated with $query1, but it is possible to inject arbitrary SQL language without using the '.

CVE-2021-25634
LibreOffice General
N/A
UNKNOWN
EPSS
0.4%
2021 CWE-295 1 PoC

LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to modify a digitally signed ODF document to insert an additional signing time timestamp which LibreOffice would incorrectly present as a valid signature signed at the bogus signing time. This issue affects: The Document Foundation LibreOffice 7-0 versions prior to 7.0.6; 7-1 versions prior to 7.1.2.

CVE-2021-41286
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2021 1 PoC

Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the application, the validity of the password is checked locally. All communication to the database backend is made via the same technical account. Consequently, an attacker can attach a debugger to the process or create a patch that manipulates the behavior of the login function. When the function always returns the success value (corresponding to a correct password), an attacker can login with any desired account, such as the administrative account of the application.

CVE-2021-24609
WP Mapa Politico España Web Windows
N/A
UNKNOWN
EPSS
0.2%
2021 CWE-79 1 PoC

The WP Mapa Politico Espana WordPress plugin before 3.7.0 does not sanitise or escape some of its settings before outputting them in attributes, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed