7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-34605
XD/E Series PLC Program Tool General
7.3
HIGH
EPSS
0.6%
2021 CWE-23 1 PoC

A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by initiating an upload program request from an infected Xinje PLC. This can result in remote code execution, information disclosure and denial of service of the system running the XINJE XD/E Series PLC Program Tool.

CVE-2021-4017
star7th/showdoc Web
7.3
HIGH
EPSS
0.1%
2021 CWE-352 1 PoC

showdoc is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-3974
vim/vim General
7.3
HIGH
EPSS
0.2%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-4170
janeczku/calibre-web Web
7.3
HIGH
EPSS
0.3%
2021 CWE-79 1 PoC

calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-25487
🔥 KEV Samsung Mobile Devices General
7.3
HIGH
EPSS
2.7%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

CVE-2021-25495
Samsung Notes General
7.3
HIGH
EPSS
0.1%
2021 CWE-122 1 PoC

A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

CVE-2021-37706
pjproject General
7.3
HIGH
EPSS
0.2%
2021 CWE-191 1 PoC

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In affected versions if the incoming STUN message contains an ERROR-CODE attribute, the header length is not checked before performing a subtraction operation, potentially resulting in an integer underflow scenario. This issue affects all users that use STUN. A malicious actor located within the victim’s network may forge and send a specially crafted UDP (STUN) message that could remotely execute arbitrary code on the victim’s

CVE-2021-33540
AXL F BK General
7.3
HIGH
EPSS
0.2%
2021 CWE-798 1 PoC

In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.

CVE-2021-30270
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
7.3
HIGH
EPSS
0.0%
2021 1 PoC

Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2021-3903
vim/vim General
7.3
HIGH
EPSS
0.4%
2021 CWE-122 1 PoC

vim is vulnerable to Heap-based Buffer Overflow

CVE-2021-22261
GitLab DevOps Web
7.3
HIGH
EPSS
0.2%
2021 1 PoC

A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary JavaScript code on the victim's behalf via malicious Jira API responses

CVE-2021-23391
calipso General
7.3
HIGH
EPSS
0.1%
2021 1 PoC

This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.

CVE-2021-42955
Software Genérico Windows
7.3
HIGH
EPSS
0.1%
2021 1 PoC

Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Access Plus Server Admin account.

CVE-2021-23682
litespeed.js General
7.3
HIGH
EPSS
5.4%
2021 2 PoCs

This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, before 0.11.1. When parsing the query string in the getJsonFromUrl function, the key that is set in the result object is not properly sanitized leading to a Prototype Pollution vulnerability.

CVE-2021-32555
apport General
7.3
HIGH
EPSS
0.1%
2021 CWE-59 1 PoC

It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.

CVE-2021-23419
open-graph General
7.3
HIGH
EPSS
0.4%
2021 1 PoC

This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.

CVE-2021-23374
ps-visitor General
7.3
HIGH
EPSS
0.8%
2021 1 PoC

This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-31843
McAfee Endpoint Security (ENS) for WIndows Windows
7.3
HIGH
EPSS
0.0%
2021 CWE-59 1 PoC

Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would otherwise not have access to via manipulating junction links to redirect McAfee folder operations to an unintended location.

CVE-2021-37695
ckeditor4 Web
7.3
HIGH
EPSS
0.7%
2021 CWE-79 3 PoCs

ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEditor 4 plugins listed above at version < 4.16.2. The problem has been recognized and patched. The fix will be available in version 4.16.2.

CVE-2021-4111
yetiforcecompany/yetiforcecrm General
7.3
HIGH
EPSS
0.2%
2021 CWE-840 1 PoC

yetiforcecrm is vulnerable to Business Logic Errors