3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-21955
Anker General
7.7
HIGH
EPSS
0.5%
2021 CWE-334 1 PoC

An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.

CVE-2021-26073
Atlassian Connect Express (ACE) General
7.7
HIGH
EPSS
0.3%
2021 1 PoC

Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Express versions from 3.0.2 before 6.6.0 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an attacker to send authenticated re-installation events to an app.

CVE-2021-34377
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to escalation of privileges, information disclosure, and denial of service.

CVE-2021-45447
Pentaho Business Analytics Server General
7.7
HIGH
EPSS
0.1%
2021 CWE-319 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.   The transmission of sensitive data in clear text allows unauthorized actors with access to the network to sniff and obtain sensitive information that can be later used to gain unauthorized access.

CVE-2021-23420
codeception/codeception General
7.7
HIGH
EPSS
0.6%
2021 1 PoC

This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.

CVE-2021-23592
topthink/framework General
7.7
HIGH
EPSS
1.0%
2021 1 PoC

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.

CVE-2021-34379
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.

CVE-2021-33601
F-Secure Internet Gatekeeper General
7.6
HIGH
EPSS
0.7%
2021 1 PoC

A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.

CVE-2021-45524
Software Genérico General
7.6
HIGH
EPSS
0.2%
2021 1 PoC

NETGEAR R8000 devices before 1.0.4.62 are affected by a buffer overflow by an authenticated user.

CVE-2021-3915
bookstackapp/bookstack General
7.6
HIGH
EPSS
0.3%
2021 CWE-434 1 PoC

bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-45493
Software Genérico General
7.6
HIGH
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of administrative credentials. This affects RAX35 before 1.0.4.102, RAX38 before 1.0.4.102, and RAX40 before 1.0.4.102.

CVE-2021-3666
fiznool/body-parser-xml General
7.6
HIGH
EPSS
0.4%
2021 CWE-1321 1 PoC

body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-3555
Indoor 2K Indoor Camera General
7.6
HIGH
EPSS
0.3%
2021 CWE-120 1 PoC

A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to achieve remote code execution. This issue affects: Eufy Indoor 2K Indoor Camera 2.0.9.3 version and prior versions.

CVE-2021-33699
SAP Fiori Client Native Mobile for Android General
7.6
HIGH
EPSS
2.2%
2021 1 PoC

Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive information.

CVE-2021-23702
object-extend General
7.6
HIGH
EPSS
0.4%
2021 1 PoC

The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.

CVE-2021-45595
Software Genérico General
7.6
HIGH
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50, RBS50Y before 2.7.3.22, RBR10 before 2.7.3.22, RBR20 before 2.7.3.22, RBR40 before 2.7.3.22, RBR50 before 2.7.3.22, RBS10 before 2.7.3.22, RBS20 before 2.7.3.22, RBS40 before 2.7.3.22, RBS50 before 2.7.3.22, RBK12 before 2.7.3.22, RBK20 before 2.7.3.22, RBK40 before 2.7.3.22, and RBK50 before 2.7.3.22.

CVE-2021-38616
Software Genérico General
7.6
HIGH
EPSS
0.9%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/user/{user-guid}/ user edition endpoint could permit any logged-in user to increase their own permissions via a user_permissions array in a PATCH request. A guest user could modify other users' profiles and much more.

CVE-2021-23407
elFinder.Net.Core General
7.5
HIGH
EPSS
0.5%
2021 1 PoC

This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.

CVE-2021-23341
prismjs General
7.5
HIGH
EPSS
1.8%
2021 3 PoCs

The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and prism-eiffel components.

CVE-2021-3649
chatwoot/chatwoot General
7.5
HIGH
EPSS
0.3%
2021 CWE-1333 1 PoC

chatwoot is vulnerable to Inefficient Regular Expression Complexity