3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25467
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-120 1 PoC

Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded library.

CVE-2021-20569
Security Secret Server General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Security Secret Server up to 11.0 could allow an attacker to enumerate usernames due to improper input validation. IBM X-Force ID: 199243.

CVE-2021-23392
locutus General
5.3
MEDIUM
EPSS
0.4%
2021 1 PoC

The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir function.

CVE-2021-3822
josdejong/jsoneditor General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-1333 1 PoC

jsoneditor is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-3647
medialize/URI.js General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

URI.js is vulnerable to URL Redirection to Untrusted Site

CVE-2021-1903
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
5.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Possible denial of service scenario can occur due to lack of length check on Channel Switch Announcement IE in beacon or probe response frame in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2021-3664
unshiftio/url-parse General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

url-parse is vulnerable to URL Redirection to Untrusted Site

CVE-2021-39189
pimcore General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-204 1 PoC

Pimcore is an open source data & experience management platform. In versions prior to 10.1.3, it is possible to enumerate usernames via the forgot password functionality. This issue is fixed in version 10.1.3. As a workaround, one may apply the available patch manually.

CVE-2021-3806
Pardus Software Center General
5.3
MEDIUM
EPSS
0.4%
2021 CWE-22 1 PoC

A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system.

CVE-2021-23368
postcss General
5.3
MEDIUM
EPSS
0.3%
2021 2 PoCs

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.

CVE-2021-21003
FL SWITCH General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-404 1 PoC

In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.

CVE-2021-34587
CC612 General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-121 1 PoC

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

CVE-2021-21344
xstream General
5.3
MEDIUM
EPSS
30.6%
2021 CWE-434 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-36199
VideoEdge General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-228 1 PoC

Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.

CVE-2021-20996
0852-0303 General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-732 1 PoC

In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

CVE-2021-3680
star7th/showdoc General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-325 1 PoC

showdoc is vulnerable to Missing Cryptographic Step

CVE-2021-25219
BIND9 General
5.3
MEDIUM
EPSS
1.0%
2021 1 PoC

In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.

CVE-2021-26085
🔥 KEV Confluence Server General ⚡ nuclei
5.3
MEDIUM
EPSS
94.0%
2021 3 PoCs

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2021-21342
xstream General
5.3
MEDIUM
EPSS
0.9%
2021 CWE-502 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in a server-side forgery request. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If

CVE-2021-41528
RISC Platform General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-863 1 PoC

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.