9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-38604
Software Genérico General
7.5
HIGH
EPSS
0.1%
2021 2 PoCs

In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.

CVE-2021-23341
prismjs General
7.5
HIGH
EPSS
1.8%
2021 3 PoCs

The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.

CVE-2021-3777
daaku/nodejs-tmpl General
7.5
HIGH
EPSS
0.4%
2021 CWE-1333 1 PoC

nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-43828
PatrowlManager General
7.5
HIGH
EPSS
0.4%
2021 CWE-269 1 PoC

PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper privilege management (IDOR) has been found in PatrowlManager. All imports findings file is placed under /media/imports/<owner_id>/<tmp_file> In that, owner_id is predictable and tmp_file is in format of import_<ownder_id>_<time_created>, for example: import_1_1639213059582.json This filename is predictable and allows anyone without logging in to download all finding import files This vulnerability is capable of allowing unlogged in users to download all finding imports file.

CVE-2021-27632
SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server) General
7.5
HIGH
EPSS
0.3%
2021 CWE-476 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-34581
750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 General
7.5
HIGH
EPSS
1.7%
2021 CWE-772 1 PoC

Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.

CVE-2021-4184
Wireshark General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-21002
FL COMSERVER General
7.5
HIGH
EPSS
0.3%
2021 CWE-772 1 PoC

In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.

CVE-2021-27628
SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher) General
7.5
HIGH
EPSS
0.3%
2021 CWE-787 1 PoC

SAP NetWeaver ABAP Server and ABAP Platform (Dispatcher), versions - KRNL32NUC - 7.22,7.22EXT, KRNL32UC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method DpRTmPrepareReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed o

CVE-2021-30301
Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible denial of service due to out of memory while processing RRC and NAS OTA message in Snapdragon Auto, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-20997
0852-0303 General
7.5
HIGH
EPSS
0.3%
2021 CWE-522 1 PoC

In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.

CVE-2021-40661
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
87.0%
2021 2 PoCs

A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Advanced Weighing Terminals Build 8.0.07 March 19, 2018 (SS Label 'IND780_8.0.07'), Version 7.2.10 June 18, 2012 (SS Label 'IND780_7.2.10'). It was possible to traverse the folders of the affected host by providing a traversal path to the 'webpage' parameter in AutoCE.ini This could allow a remote unauthenticated adversary to access additional files on the affected system. This could also allow the adversary to perform further enumeration against the affected host to identify the

CVE-2021-3804
nervjs/taro General
7.5
HIGH
EPSS
0.2%
2021 CWE-1333 1 PoC

taro is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-21817
D-Link General
7.5
HIGH
EPSS
1.9%
2021 CWE-200 1 PoC

An information disclosure vulnerability exists in the Zebra IP Routing Manager functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-43447
Software Genérico General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the document editor allows attackers to edit documents without authentication.

CVE-2021-27665
exacqVision Web Service General
7.5
HIGH
EPSS
0.3%
2021 CWE-190 1 PoC

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition.

CVE-2021-32751
gradle General
7.5
HIGH
EPSS
0.3%
2021 CWE-78 1 PoC

Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to change environment variables for the user running the script. This may impact those who use `gradlew` on Unix-like systems or use the scripts generated by Gradle in thieir application on Unix-like systems. For this vulnerability to be exploitable, an attacker needs to be able to set the value of particular environment variables and have those environment variabl

CVE-2021-27597
SAP NetWeaver AS for ABAP (RFC Gateway) General
7.5
HIGH
EPSS
0.3%
2021 CWE-125 2 PoCs

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method memmove() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-46749
Ryzen™ 2000 Series Desktop Processors “Pinnacle Ridge” General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

CVE-2021-36630
Software Genérico General
7.5
HIGH
EPSS
39.9%
2021 1 PoC

DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote attackers to perform DOS attacks via crafted request.