3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-21909
Garrett Metal Detectors General
6.0
MEDIUM
EPSS
0.5%
2021 CWE-22 1 PoC

Specially-crafted command line arguments can lead to arbitrary file deletion in the del .cnt|.log file delete command. An attacker can provide malicious inputs to trigger this vulnerability

CVE-2021-21595
PowerScale OneFS General
6.0
MEDIUM
EPSS
0.1%
2021 CWE-77 1 PoC

Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts Smartlock WORM compliance mode clusters as a critical vulnerability and Dell recommends to update/upgrade at the earliest opportunity.

CVE-2021-25469
Samsung Mobile Devices General
6.0
MEDIUM
EPSS
0.0%
2021 CWE-120 1 PoC

A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.

CVE-2021-25520
Samsung Internet General
5.9
MEDIUM
EPSS
0.3%
2021 CWE-20 1 PoC

Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.

CVE-2021-43309
uri-template-lite General
5.9
MEDIUM
EPSS
0.3%
2021 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.expand" method

CVE-2021-27627
SAP Internet Graphics Service General
5.9
MEDIUM
EPSS
0.5%
2021 CWE-787 1 PoC

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-36808
Sophos Secure Workspace for Android General
5.9
MEDIUM
EPSS
0.0%
2021 1 PoC

A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

CVE-2021-43306
jquery-validation General
5.9
MEDIUM
EPSS
0.8%
2021 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method

CVE-2021-43055
TIBCO eFTL - Community Edition General
5.9
MEDIUM
EPSS
0.2%
2021 1 PoC

The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows clients to inherit the permissions of the client that initially connected on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO eFTL - Community Edition: versions 6.7.2 and below, TIBCO eFTL - Developer Edition: versions 6.7.2 and below, and TIBCO eFTL - Enterprise Edition: versions 6.7.2 and below.

CVE-2021-38862
Data Risk Manager General
5.9
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Data Risk Manager (iDNA) 2.0.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 207980.

CVE-2021-38919
QRadar SIEM General
5.9
MEDIUM
EPSS
0.4%
2021 1 PoC

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-Force ID: 210021

CVE-2021-25457
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.

CVE-2021-40528
Software Genérico General
5.9
MEDIUM
EPSS
0.1%
2021 1 PoC

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration attack against OpenPGP.

CVE-2021-4070
v2fly/v2ray-core General
5.9
MEDIUM
EPSS
0.2%
2021 CWE-193 1 PoC

Off-by-one Error in GitHub repository v2fly/v2ray-core prior to 4.44.0.

CVE-2021-27624
SAP Internet Graphics Service General
5.9
MEDIUM
EPSS
0.5%
2021 CWE-787 1 PoC

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CiXMLIStreamRawBuffer::readRaw () which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-27626
SAP Internet Graphics Service General
5.9
MEDIUM
EPSS
0.5%
2021 CWE-787 1 PoC

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-43308
markdown-link-extractor General
5.9
MEDIUM
EPSS
0.4%
2021 CWE-1333 1 PoC

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function

CVE-2021-27622
SAP Internet Graphics Service General
5.9
MEDIUM
EPSS
0.5%
2021 CWE-787 1 PoC

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVE-2021-23336
python/cpython General
5.9
MEDIUM
EPSS
0.3%
2021 4 PoCs

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the se