3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-21349
xstream General
6.1
MEDIUM
EPSS
6.7%
2021 CWE-502 4 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-22141
Kibana General
6.1
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

An open redirect flaw was found in Kibana versions before 7.13.0 and 6.8.16. If a logged in user visits a maliciously crafted URL, it could result in Kibana redirecting the user to an arbitrary website.

CVE-2021-25370
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.5%
2021 2 PoCs

An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

CVE-2021-25512
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

CVE-2021-41943
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2021 1 PoC

Logrhythm Web Console 7.4.9 allows for HTML tag injection through Contextualize Action -> Create a new Contextualize Action -> Inject your HTML tag in the name field.

CVE-2021-45522
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2021 1 PoC

NETGEAR XR1000 devices before 1.0.0.58 are affected by a hardcoded password.

CVE-2021-25382
Samsung Mobile Devices General
6.1
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.

CVE-2021-21346
xstream General
6.1
MEDIUM
EPSS
3.7%
2021 CWE-434 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-21347
xstream General
6.1
MEDIUM
EPSS
3.3%
2021 CWE-434 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-3458
MM1000 MoCA Adapter General
6.1
MEDIUM
EPSS
0.0%
2021 CWE-287 1 PoC

The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.

CVE-2021-33707
SAP NetWeaver (Knowledge Management) General
6.1
MEDIUM
EPSS
0.6%
2021 CWE-601 1 PoC

SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via a URL stored in a component. This could enable the attacker to compromise the user's confidentiality and integrity.

CVE-2021-25371
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
1.6%
2021 CWE-912 2 PoCs

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

CVE-2021-45602
Software Genérico General
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130, and XR700 before 1.0.1.46.

CVE-2021-45603
Software Genérico General
6.1
MEDIUM
EPSS
0.0%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. A UPnP request reveals a device's serial number, which can be used for a password reset. This affects D7800 before 1.0.1.66, EX2700 before 1.0.1.68, WN3000RPv2 before 1.0.0.90, WN3000RPv3 before 1.0.2.100, LBR1020 before 2.6.5.20, LBR20 before 2.6.5.32, R6700AX before 1.0.10.110, R7800 before 1.0.2.86, R8900 before 1.0.5.38, R9000 before 1.0.5.38, RAX10 before 1.0.10.110, RAX120v1 before 1.2.3.28, RAX120v2 before 1.2.3.28, RAX70 before 1.0.10.110, RAX78 before 1.0.10.110, XR450 before 2.3.2.130, XR500 before 2.3.2.130

CVE-2021-36322
Networking X-Series General
6.1
MEDIUM
EPSS
0.7%
2021 CWE-20 1 PoC

Dell Networking X-Series firmware versions prior to 3.0.1.8 contain a host header injection vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by injecting arbitrary host header values to poison the web-cache or trigger redirections.

CVE-2021-46759
Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 General
6.1
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

CVE-2021-45525
Software Genérico General
6.1
MEDIUM
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an authenticated user. This affects EX7000 before 1.0.1.80, R6400 before 1.0.1.50, R6400v2 before 1.0.4.118, R6700 before 1.0.2.8, R6700v3 before 1.0.4.118, R6900 before 1.0.2.8, R6900P before 1.3.2.124, R7000 before 1.0.9.88, R7000P before 1.3.2.124, R7900 before 1.0.3.18, R7900P before 1.4.1.50, R8000 before 1.0.4.46, R8000P before 1.4.1.50, RAX80 before 1.0.1.56, and WNR3500Lv2 before 1.2.0.62.

CVE-2021-25372
🔥 KEV Samsung Mobile Devices General
6.1
MEDIUM
EPSS
1.8%
2021 2 PoCs

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

CVE-2021-25490
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.0%
2021 CWE-287 1 PoC

A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.

CVE-2021-21909
Garrett Metal Detectors General
6.0
MEDIUM
EPSS
0.5%
2021 CWE-22 1 PoC

Specially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can provide malicious inputs to trigger this vulnerability