3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-34589
CC612 General
7.5
HIGH
EPSS
0.3%
2021 CWE-200 1 PoC

In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.

CVE-2021-37624
freeswitch General
7.5
HIGH
EPSS
2.3%
2021 CWE-287 1 PoC

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.10.7, FreeSWITCH does not authenticate SIP MESSAGE requests, leading to spam and message spoofing. By default, SIP requests of the type MESSAGE (RFC 3428) are not authenticated in the affected versions of FreeSWITCH. MESSAGE requests are relayed to SIP user agents registered with the FreeSWITCH server without requiring any authentication. Although this behaviour can be changed by setting the `au

CVE-2021-27633
SAP NetWeaver AS for ABAP (RFC Gateway) General
7.5
HIGH
EPSS
0.3%
2021 CWE-787 2 PoCs

SAP NetWeaver AS for ABAP (RFC Gateway), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73,7.77,7.81,7.82,7.83, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method ThCPIC() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-20123
🔥 KEV Draytek VigorConnect General ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2021 1 PoC

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CVE-2021-34593
CODESYS V2 General
7.5
HIGH
EPSS
4.3%
2021 CWE-755 3 PoCs

In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.

CVE-2021-32568
zmister2016/mrdoc General
7.5
HIGH
EPSS
0.3%
2021 CWE-502 1 PoC

mrdoc is vulnerable to Deserialization of Untrusted Data

CVE-2021-1964
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Possible buffer over read due to improper validation of IE size while parsing beacon from peer device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2021-23360
killport General
7.5
HIGH
EPSS
0.8%
2021 1 PoC

This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command touch success to be executed, leading to the creation of a file called success.

CVE-2021-3807
chalk/ansi-regex General
7.5
HIGH
EPSS
0.2%
2021 CWE-1333 2 PoCs

ansi-regex is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-23460
min-dash General
7.5
HIGH
EPSS
0.5%
2021 2 PoCs

The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.

CVE-2021-1943
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

CVE-2021-33541
ILC1x General
7.5
HIGH
EPSS
1.3%
2021 CWE-770 1 PoC

Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's network communication module. A successful attack stops all network communication. To restore the network connectivity the device needs to be restarted. The automation task is not affected.

CVE-2021-4184
Wireshark General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

CVE-2021-34581
750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 General
7.5
HIGH
EPSS
1.7%
2021 CWE-772 1 PoC

Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenticated attacker to cause DoS on the device.

CVE-2021-30328
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.2%
2021 1 PoC

Possible assertion due to improper validation of invalid NR CSI-IM resource configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-23430
startserver General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

All versions of package startserver are vulnerable to Directory Traversal due to missing sanitization.

CVE-2021-21902
Garrett Metal Detectors General
7.5
HIGH
EPSS
0.4%
2021 CWE-303 1 PoC

An authentication bypass vulnerability exists in the CMA run_server_6877 functionality of Garrett Metal Detectors iC Module CMA Version 5.0. A properly-timed network connection can lead to authentication bypass via session hijacking. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2021-1907
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible buffer overflow due to lack of length check in BA request in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-3794
vuelidate/vuelidate General
7.5
HIGH
EPSS
0.3%
2021 CWE-1333 1 PoC

vuelidate is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-3326
Software Genérico General
7.5
HIGH
EPSS
0.2%
2021 2 PoCs

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.