Base de datos CVE
Archivo de vulnerabilidades conocidas (CVE) con puntuación CVSS, gravedad, productos y fabricantes afectados. Filtra por año y severidad.
- CVE-2021-22894Alta8.8
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
- CVE-2021-21985Crítica9.8
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual SAN Health Check plug-in which is enabled by default in vCenter Server. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlying operating system that hosts vCenter Server.
- CVE-2021-27562Media5.5
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode.
- CVE-2021-29256Alta8.8
. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
- CVE-2021-28799Crítica10.0
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
- CVE-2021-31207Media6.6
Microsoft Exchange Server Security Feature Bypass Vulnerability
- CVE-2021-31166Crítica9.8
HTTP Protocol Stack Remote Code Execution Vulnerability
- CVE-2021-28664Alta8.8
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages. This affects Bifrost r0p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r8p0 through r30p0 before r31p0.
- CVE-2021-28663Alta8.8
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free. This affects Bifrost r0p0 through r28p0 before r29p0, Valhall r19p0 through r28p0 before r29p0, and Midgard r4p0 through r30p0.
- CVE-2021-31755Crítica9.8
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.
- CVE-2021-1906Media6.2
Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- CVE-2021-1905Alta8.4
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
- CVE-2021-32030Crítica9.8
The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN.
- CVE-2021-1498Crítica9.8
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-1497Crítica9.8
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-21551Alta8.8
El controlador dbutil_2_3.sys de Dell contiene una vulnerabilidad de control de acceso insuficiente que puede dar lugar a una escalada de privilegios, denegación de servicio o divulgación de información. Se requiere acceso local de usuario autenticado.
- CVE-2021-20090Crítica9.8
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
- CVE-2021-29442Alta8.6
Nacos es una plataforma diseñada para el descubrimiento dinámico de servicios y la gestión de la configuración y de los servicios. En Nacos antes de la versión 1.4.1, ConfigOpsController permite al usuario realizar operaciones de gestión como consultar la base de datos o incluso eliminarla por completo. Mientras que el endpoint /data/remove está correctamente protegido con la anotación @Secured, el endpoint /derby no está protegido y puede ser accedido abiertamente por usuarios no autenticados. Estos endpoints solo son válidos cuando se utiliza almacenamiento embebido (derby DB), por lo que este problema no debería afectar a aquellas instalaciones que utilizan almacenamiento externo (p. ej. mysql)
- CVE-2021-29441Alta8.6
Nacos es una plataforma diseñada para el descubrimiento dinámico de servicios y la configuración y la gestión de servicios. En Nacos antes de la versión 1.4.1, cuando está configurado para usar autenticación (-Dnacos.core.auth.enabled=true) Nacos utiliza el filtro servlet AuthFilter para aplicar la autenticación. Este filtro tiene una backdoor que permite a los servidores Nacos omitir este filtro y, por tanto, omitir las comprobaciones de autenticación. Este mecanismo se basa en la cabecera HTTP user-agent, por lo que puede falsificarse fácilmente. Este problema puede permitir a cualquier usuario llevar a cabo cualquier tarea administrativa en el servidor Nacos.
- CVE-2021-21224Alta8.8
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
This product uses the NVD API but is not endorsed or certified by the NVD.