Database CVE
Archivio delle vulnerabilità note (CVE) con punteggio CVSS, gravità, prodotti e vendor coinvolti. Filtra per anno e severità, collegato ai nostri articoli.
- CVE-2021-1498Critica9.8
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-1497Critica9.8
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
- CVE-2021-21551Alta8.8
Il driver Dell dbutil_2_3.sys contiene una vulnerabilità di controllo degli accessi insufficiente che può portare a escalation dei privilegi, denial of service o divulgazione di informazioni. È richiesto l'accesso di un utente locale autenticato.
- CVE-2021-20090Critica9.8
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
- CVE-2021-29442Alta8.6
Nacos è una piattaforma progettata per la service discovery dinamica e la gestione della configurazione e dei servizi. In Nacos prima della versione 1.4.1, il ConfigOpsController consente all'utente di eseguire operazioni di gestione come interrogare il database o addirittura cancellarlo. Mentre l'endpoint /data/remove è correttamente protetto con l'annotazione @Secured, l'endpoint /derby non è protetto e può essere acceduto liberamente da utenti non autenticati. Questi endpoint sono validi solo quando si utilizza lo storage embedded (derby DB), quindi questo problema non dovrebbe riguardare le installazioni che utilizzano lo storage esterno (e.g. mysql)
- CVE-2021-29441Alta8.6
Nacos è una piattaforma progettata per la service discovery dinamica e la gestione della configurazione e dei servizi. In Nacos prima della versione 1.4.1, quando configurato per utilizzare l'autenticazione (-Dnacos.core.auth.enabled=true) Nacos utilizza il filtro servlet AuthFilter per imporre l'autenticazione. Questo filtro ha una backdoor che consente ai server Nacos di bypassare questo filtro e quindi di saltare i controlli di autenticazione. Questo meccanismo si basa sull'header HTTP user-agent, quindi può essere facilmente spoofato. Questo problema può consentire a qualsiasi utente di eseguire qualsiasi attività amministrativa sul server Nacos.
- CVE-2021-21224Alta8.8
Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVE-2021-21220Alta8.8
Insufficient validation of untrusted input in V8 in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-21206Alta8.8
Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2021-22205Critica10.0
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
- CVE-2021-22204Media6.8
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- CVE-2021-22893Critica10.0
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
- CVE-2021-20023Media4.9
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
- CVE-2021-3493Alta8.8
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts, an attacker could use this to gain elevated privileges.
- CVE-2020-2509Critica9.8
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later
- CVE-2021-28310Alta7.8
Win32k Elevation of Privilege Vulnerability
- CVE-2021-20022Alta7.2
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
- CVE-2021-20021Critica9.8
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
- CVE-2021-1879Media6.1
This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and iPadOS 14.4.2, watchOS 7.3.3. Processing maliciously crafted web content may lead to universal cross site scripting. Apple is aware of a report that this issue may have been actively exploited..
- CVE-2021-1871Critica9.8
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
This product uses the NVD API but is not endorsed or certified by the NVD.