This is a list of recent vulnerabilities for which exploits are available.
CVE, Title, Vendor
Description
CVSS v3.1 Base Score
Date Created
Date Updated
CVE-2021-26937
Denial of Service Vulnerability in GNU Screen
Gnu, Debian, and Fedora Project
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
02/09/2021
05/26/2021
CVE-2021-26120
Code Injection Vulnerability in Smarty
Smarty, Debian
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
02/21/2021
05/26/2021
CVE-2021-20231
Memory Corruption Vulnerability in Gnutls
Gnu, Redhat, NetApp, and Fedora Project
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
Base Score: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
03/12/2021
06/01/2021
CVE-2021-31800
Arbitrary Code Execution Vulnerability in SMbserver Instance
SecureAuth, Fedora Project
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
05/05/2021
05/26/2021
CVE-2021-29921
Weak Authentication Control in Python Version < 3,9,5
Python
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
05/06/2021
06/01/2021
CVE-2021-28799
Weak Authorization Vulnerability in QNAP
Qnap
An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
05/12/2021
06/01/2021
CVE-2021-31474
Arbitrary Code Execution Vulnerability in SolarWinds
Solarwinds
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-12213.