3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-27596
SAP 3D Visual Enterprise Viewer General
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2021-27595
SAP 3D Visual Enterprise Viewer General
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.

CVE-2021-3874
bookstackapp/bookstack General
4.3
MEDIUM
EPSS
0.4%
2021 CWE-22 1 PoC

bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2021-20371
Rational Collaborative Lifecycle Management General
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195516.

CVE-2021-4194
bookstackapp/bookstack General
4.3
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

bookstack is vulnerable to Improper Access Control

CVE-2021-32002
SiteManager General
4.3
MEDIUM
EPSS
0.0%
2021 CWE-284 1 PoC

Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to gather network information and configuration of the SiteManager. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.

CVE-2021-38869
QRadar SIEM General
4.3
MEDIUM
EPSS
0.3%
2021 1 PoC

IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.

CVE-2021-4146
pimcore/pimcore General
4.3
MEDIUM
EPSS
0.0%
2021 CWE-840 1 PoC

Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.

CVE-2021-27658
exacqVision Enterprise Manager General
4.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2021-45074
JFrog Artifactory General
4.3
MEDIUM
EPSS
0.3%
2021 CWE-284 1 PoC

JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to delete other known users OAuth token, which will force a reauthentication on an active session or in the next UI session.

CVE-2021-31600
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2021 1 PoC

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all valid usernames.

CVE-2021-36201
C•CURE 9000 General
4.3
MEDIUM
EPSS
0.1%
2021 CWE-204 1 PoC

Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

CVE-2021-37865
Mattermost General
4.3
MEDIUM
EPSS
0.6%
2021 CWE-400 1 PoC

Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while drafting a post, which allows authenticated users to cause resource exhaustion while processing the file, resulting in server-side Denial of Service.

CVE-2021-1896
Snapdragon Compute, Snapdragon Connectivity General
4.3
MEDIUM
EPSS
0.0%
2021 1 PoC

Weak configuration in WLAN could cause forwarding of unencrypted packets from one client to another in Snapdragon Compute, Snapdragon Connectivity

CVE-2021-29700
Sterling B2B Integrator General
4.3
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sensitive information from configuration files that could aid in further attacks against the system. IBM X-Force ID: 200656.

CVE-2021-25378
SmartThings General
4.3
MEDIUM
EPSS
0.4%
2021 CWE-20 2 PoCs

Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.

CVE-2021-34393
NVIDIA Jetson TX2 series, TX2 NX, AGX Xavier series, Xavier NX General
4.2
MEDIUM
EPSS
0.2%
2021 1 PoC

Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

CVE-2021-34394
NVIDIA Jetson TX2 series, TX2 NX, AGX Xavier series, Xavier NX General
4.2
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data modification.

CVE-2021-39078
Security Guardium General
4.1
MEDIUM
EPSS
0.0%
2021 1 PoC

IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 215589.

CVE-2021-3967
zulip/zulip General
4.1
MEDIUM
EPSS
0.3%
2021 CWE-284 1 PoC

Improper Access Control in GitHub repository zulip/zulip prior to 4.10.