7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-34470
Microsoft Exchange Server 2013 Cumulative Update 23 Windows
8.0
HIGH
EPSS
4.7%
2021 2 PoCs

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2021-32819
squirrelly Web ⚡ nuclei
8.0
HIGH
EPSS
89.6%
2021 CWE-200 1 PoC

Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration options remote code execution may be triggered in downstream applications. This issue is fixed in version 9.0.0. For complete details refer to the referenced GHSL-2021-023.

CVE-2021-3985
kevinpapst/kimai2 Web
8.0
HIGH
EPSS
0.4%
2021 CWE-79 1 PoC

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-3745
flatcore/flatcore-cms Web
8.0
HIGH
EPSS
0.4%
2021 CWE-434 1 PoC

flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-3815
fabiocaccamo/utils.js General
8.0
HIGH
EPSS
0.2%
2021 CWE-1321 1 PoC

utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-27246
AC1750 Networking
8.0
HIGH
EPSS
12.4%
2021 CWE-121 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MAC addresses by the tdpServer endpoint. A crafted TCP message can write stack pointers to the stack. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-12306.

CVE-2021-30481
Software Genérico General
8.0
HIGH
EPSS
7.5%
2021 3 PoCs

Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

CVE-2021-21300
git Windows
8.0
HIGH
EPSS
64.5%
2021 CWE-59 15 PoCs

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March

CVE-2021-3961
snipe/snipe-it Web
8.0
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-25960
SuiteCRM General
8.0
HIGH
EPSS
0.5%
2021 CWE-1236 1 PoC

In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.

CVE-2021-32003
SiteManager General
8.0
HIGH
EPSS
0.0%
2021 CWE-523 1 PoC

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

CVE-2021-41503
Software Genérico General
8.0
HIGH
EPSS
0.4%
2021 1 PoC

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-3968
vim/vim General
8.0
HIGH
EPSS
0.8%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-35234
Orion Core Database
8.0
HIGH
EPSS
0.8%
2021 CWE-89 1 PoC

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

CVE-2021-35499
TIBCO Nimbus Web
8.0
HIGH
EPSS
0.4%
2021 1 PoC

The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a legitimate user with network access to execute scripts targeting the affected system or the victim's local system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: versions 10.4.0 and below.

CVE-2021-31581
Provisioning Manager Engine (PME) Database ⚡ nuclei
7.9
HIGH
EPSS
9.2%
2021 CWE-269 0 PoCs

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

CVE-2021-25502
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

CVE-2021-25361
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-22 2 PoCs

An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.

CVE-2021-33183
Synology Docker DevOps
7.9
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.

CVE-2021-34373
NVIDIA Jetson TX1 General
7.9
HIGH
EPSS
0.1%
2021 1 PoC

Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.