3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25395
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.2%
2021 CWE-362 1 PoC

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

CVE-2021-36293
VNX2 General
6.4
MEDIUM
EPSS
0.1%
2021 CWE-78 1 PoC

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

CVE-2021-3818
getgrav/grav General
6.3
MEDIUM
EPSS
0.3%
2021 CWE-565 1 PoC

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking

CVE-2021-3846
firefly-iii/firefly-iii General
6.3
MEDIUM
EPSS
0.2%
2021 CWE-434 1 PoC

firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type

CVE-2021-25511
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

CVE-2021-45552
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58, R7500v2 before 1.0.3.48, R7800 before 1.0.2.68, R8900 before 1.0.5.2, R9000 before 1.0.5.2, RAX120 before 1.0.1.108, and XR700 before 1.0.1.20.

CVE-2021-23888
McAfee ePolicy Orchestrator (ePO) General
6.3
MEDIUM
EPSS
0.5%
2021 CWE-601 1 PoC

Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could cause an authenticated ePO user to load an untrusted site in an ePO iframe which could steal information from the authenticated user.

CVE-2021-27254
R7800 General
6.3
MEDIUM
EPSS
0.1%
2021 CWE-259 1 PoC

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-12287.

CVE-2021-21473
SAP NetWeaver AS ABAP and ABAP Platform (SRM_RFC_SUBMIT_REPORT) General
6.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVE-2021-34387
NVIDIA Jetson TX1 General
6.3
MEDIUM
EPSS
0.0%
2021 1 PoC

The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.

CVE-2021-34386
NVIDIA Jetson TX1 General
6.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation can cause the multiplication of count and size can overflow, which might lead to heap overflows.

CVE-2021-38615
Software Genérico General
6.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information.

CVE-2021-29449
pi-hole General
6.3
MEDIUM
EPSS
11.4%
2021 CWE-269 1 PoC

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

CVE-2021-23348
portprocesses General
6.3
MEDIUM
EPSS
1.1%
2021 1 PoC

This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-38539
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.10, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

CVE-2021-35221
Orion Platform General
6.3
MEDIUM
EPSS
0.4%
2021 CWE-284 1 PoC

Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

CVE-2021-4264
dustjs General
6.3
MEDIUM
EPSS
0.7%
2021 CWE-1321 1 PoC

A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is ddb6523832465d38c9d80189e9de60519ac307c3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216464.

CVE-2021-3758
bookstackapp/bookstack General
6.3
MEDIUM
EPSS
0.2%
2021 CWE-918 1 PoC

bookstack is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2021-23363
kill-by-port General
6.3
MEDIUM
EPSS
1.0%
2021 1 PoC

This affects the package kill-by-port before 0.0.2. If (attacker-controlled) user input is given to the killByPort function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-27255
R7800 General
6.3
MEDIUM
EPSS
1.7%
2021 CWE-306 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware version 1.0.2.76. Authentication is not required to exploit this vulnerability. The specific flaw exists within the refresh_status.aspx endpoint. The issue results from a lack of authentication required to start a service on the server. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-12360.