3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-34390
NVIDIA Jetson TX1 General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

CVE-2021-21342
xstream General
5.3
MEDIUM
EPSS
0.9%
2021 CWE-502 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in a server-side forgery request. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If

CVE-2021-41528
RISC Platform General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-863 1 PoC

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

CVE-2021-21348
xstream General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-400 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-36095
((OTRS)) Community Edition General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-200 1 PoC

Malicious attacker is able to find out valid user logins by using the "lost password" feature. This issue affects: OTRS AG ((OTRS)) Community Edition version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

CVE-2021-40392
MXView Series General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-319 1 PoC

An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.

CVE-2021-25522
Samsung Capture General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.

CVE-2021-43448
Software Genérico General
5.3
MEDIUM
EPSS
0.4%
2021 1 PoC

ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allow an attacker to spoof the names of users who interact with a document, if the document id is known.

CVE-2021-20995
0852-0303 General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-312 1 PoC

In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.

CVE-2021-23364
browserslist General
5.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.

CVE-2021-1967
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Possible stack buffer overflow due to lack of check on the maximum number of post NAN discovery attributes while processing a NAN Match event in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-4432
FTP Server General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-404 3 PoCs

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250719.

CVE-2021-47768
ImportExportTools NG General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-79 2 PoCs

ImportExportTools NG 10.0.4 contains a persistent HTML injection vulnerability in the email export module that allows remote attackers to inject malicious HTML payloads. Attackers can send emails with crafted HTML in the subject that execute during HTML export, potentially compromising user data or session credentials.

CVE-2021-36093
((OTRS)) Community Edition General
5.3
MEDIUM
EPSS
0.5%
2021 CWE-185 1 PoC

It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

CVE-2021-3980
elgg/elgg General
5.3
MEDIUM
EPSS
0.6%
2021 CWE-359 1 PoC

elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVE-2021-23362
hosted-git-info General
5.3
MEDIUM
EPSS
0.6%
2021 2 PoCs

The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expression shortcutMatch in the fromUrl function in index.js. The affected regular expression exhibits polynomial worst-case time complexity.

CVE-2021-23425
trim-off-newlines General
5.3
MEDIUM
EPSS
0.4%
2021 2 PoCs

All versions of package trim-off-newlines are vulnerable to Regular Expression Denial of Service (ReDoS) via string processing.

CVE-2021-28164
Eclipse Jetty General ⚡ nuclei
5.3
MEDIUM
EPSS
93.5%
2021 CWE-200 5 PoCs

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.

CVE-2021-47078
Linux General
5.3
MEDIUM
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Clear all QP fields if creation failed rxe_qp_do_cleanup() relies on valid pointer values in QP for the properly created ones, but in case rxe_qp_from_init() failed it was filled with garbage and caused tot the following error. refcount_t: underflow; use-after-free. WARNING: CPU: 1 PID: 12560 at lib/refcount.c:28 refcount_warn_saturate+0x1d1/0x1e0 lib/refcount.c:28 Modules linked in: CPU: 1 PID: 12560 Comm: syz-executor.4 Not tainted 5.12.0-syzkaller #0 Hardware name: Google Google Compute Engine/Google

CVE-2021-4119
bookstackapp/bookstack General
5.3
MEDIUM
EPSS
0.4%
2021 CWE-284 1 PoC

bookstack is vulnerable to Improper Access Control