3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-23663
sey General
6.5
MEDIUM
EPSS
0.5%
2021 1 PoC

All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

CVE-2021-36326
Dell EMC Streaming Data Platform General
6.5
MEDIUM
EPSS
0.4%
2021 CWE-757 1 PoC

Dell EMC Streaming Data Platform, versions prior to 1.3 contain an SSL Strip Vulnerability in the User Interface (UI). A remote unauthenticated attacker could potentially exploit this vulnerability, leading to a downgrade in the communications between the client and server into an unencrypted format.

CVE-2021-36329
Dell EMC Streaming Data Platform General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-639 1 PoC

Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.

CVE-2021-25973
publify_core General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-285 1 PoC

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

CVE-2021-22570
Protobuf General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

CVE-2021-21792
IObit General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-782 1 PoC

An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read four bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.

CVE-2021-41183
jquery-ui General
6.5
MEDIUM
EPSS
2.9%
2021 CWE-79 5 PoCs

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.

CVE-2021-25375
Samsung Email General
6.5
MEDIUM
EPSS
0.4%
2021 CWE-200 2 PoCs

Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.

CVE-2021-1957
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music General
6.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper Access Control when ACL link encryption is failed and ACL link is not disconnected during reconnection with paired device in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2021-3734
yourls/yourls General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-1021 1 PoC

yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames

CVE-2021-1918
Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
6.5
MEDIUM
EPSS
0.0%
2021 1 PoC

Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-25920
openemr General
6.5
MEDIUM
EPSS
0.2%
2021 1 PoC

In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating a new user, which leads to a malicious user able to read and send sensitive messages on behalf of the victim user.

CVE-2021-27257
R7800 General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-295 1 PoC

This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the downloading of files via FTP. The issue results from the lack of proper validation of the certificate presented by the server. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-12362.

CVE-2021-21790
IOBit General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-782 1 PoC

An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.

CVE-2021-4000
star7th/showdoc General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

showdoc is vulnerable to URL Redirection to Untrusted Site

CVE-2021-33104
Intel(R) OFU software General
6.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-28829
TIBCO Administrator - Enterprise Edition General
6.5
MEDIUM
EPSS
0.3%
2021 1 PoC

The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition for z/Linux, and TIBCO Administrator - Enterprise Edition for z/Linux contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute a persistent CSV injection attack from the affected system. A successful at

CVE-2021-33678
SAP NetWeaver AS ABAP (Reconciliation Framework) General
6.5
MEDIUM
EPSS
2.2%
2021 CWE-95 2 PoCs

A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.

CVE-2021-21468
SAP Business Warehouse General
6.5
MEDIUM
EPSS
0.4%
2021 2 PoCs

The BW Database Interface does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges that allows the user to practically read out any database table.

CVE-2021-3990
star7th/showdoc General
6.5
MEDIUM
EPSS
0.3%
2021 CWE-338 1 PoC

showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)