7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3968
vim/vim General
8.0
HIGH
EPSS
0.8%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-30481
Software Genérico General
8.0
HIGH
EPSS
7.5%
2021 3 PoCs

Valve Steam before 2021-04-17, when a Source engine game is installed, allows remote authenticated users to execute arbitrary code because of a buffer overflow that occurs for a Steam invite after one click.

CVE-2021-41503
Software Genérico General
8.0
HIGH
EPSS
0.4%
2021 1 PoC

DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authentication for the devices command interface allows attack vectors that may compromise the cameras configuration and allow malicious users on the LAN to access the device. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

CVE-2021-32003
SiteManager General
8.0
HIGH
EPSS
0.0%
2021 CWE-523 1 PoC

Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

CVE-2021-25960
SuiteCRM General
8.0
HIGH
EPSS
0.5%
2021 CWE-1236 1 PoC

In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file and opens it, the payload gets executed. This was not fixed properly as part of CVE-2020-15301, allowing the attacker to bypass the security measure.

CVE-2021-3985
kevinpapst/kimai2 Web
8.0
HIGH
EPSS
0.4%
2021 CWE-79 1 PoC

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-21300
git Windows
8.0
HIGH
EPSS
64.5%
2021 CWE-59 15 PoCs

Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause just-checked out script to be executed while cloning onto a case-insensitive file system such as NTFS, HFS+ or APFS (i.e. the default file systems on Windows and macOS). Note that clean/smudge filters have to be configured for that. Git for Windows configures Git LFS by default, and is therefore vulnerable. The problem has been patched in the versions published on Tuesday, March

CVE-2021-27246
AC1750 Networking
8.0
HIGH
EPSS
12.4%
2021 CWE-121 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MAC addresses by the tdpServer endpoint. A crafted TCP message can write stack pointers to the stack. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-12306.

CVE-2021-3961
snipe/snipe-it Web
8.0
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-39170
pimcore Web
8.0
HIGH
EPSS
0.0%
2021 CWE-116 1 PoC

Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could add XSS code as a value of custom metadata on assets. There is a patch for this issue in Pimcore version 10.1.2. As a workaround, users may apply the patch manually.

CVE-2021-23273
TIBCO Spotfire Analyst Web Cloud
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Desktop, and TIBCO Spotfire Server contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a stored Cross Site Scripting (XSS) attack on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Spotfire Analyst: versions 10.3.3 and below, versions 10.10.0, 10.10.1, and 10.1

CVE-2021-3745
flatcore/flatcore-cms Web
8.0
HIGH
EPSS
0.4%
2021 CWE-434 1 PoC

flatcore-cms is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-25961
SuiteCRM General
8.0
HIGH
EPSS
0.3%
2021 CWE-640 1 PoC

In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.

CVE-2021-25962
shuup General
8.0
HIGH
EPSS
0.4%
2021 CWE-1236 1 PoC

“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inject payloads in the name input field in the billing address while buying a product. When a store administrator accesses the reports page to export the data as an Excel file and opens it, the payload gets executed.

CVE-2021-23271
TIBCO EBX Web
8.0
HIGH
EPSS
0.3%
2021 1 PoC

The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows a low privileged attacker with network access to execute a Stored Cross Site Scripting (XSS) attack on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.9.12 and below.

CVE-2021-2129
VM VirtualBox Database
7.9
HIGH
EPSS
0.1%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data

CVE-2021-25470
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-94 1 PoC

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

CVE-2021-31581
Provisioning Manager Engine (PME) Database ⚡ nuclei
7.9
HIGH
EPSS
9.2%
2021 CWE-269 0 PoCs

The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command. This command launches a standard vi editor interface which can then be escaped. This issue was resolved in Akkadian OVA appliance version 3.0 (and later), Akkadian Provisioning Manager 5.0.2 (and later), and Akkadian Appliance Manager 3.3.0.314-4a349e0 (and later).

CVE-2021-33183
Synology Docker DevOps
7.9
HIGH
EPSS
0.1%
2021 CWE-22 1 PoC

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary files via unspecified vectors.

CVE-2021-25502
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2021 CWE-269 1 PoC

A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.