3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-40338
Software Genérico General
3.7
LOW
EPSS
0.2%
2021 1 PoC

Hitachi Energy LinkOne product, has a vulnerability due to a web server misconfiguration, that enables debug mode and reveals the full path of the filesystem directory when an attacker generates errors during a query operation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

CVE-2021-21971
Sealevel General
3.7
LOW
EPSS
0.4%
2021 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2021-25471
Samsung Mobile Devices General
3.7
LOW
EPSS
0.1%
2021 CWE-20 1 PoC

A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.

CVE-2021-37862
Mattermost General
3.7
LOW
EPSS
0.2%
2021 CWE-754 1 PoC

Mattermost 6.0 and earlier fails to sufficiently validate the email address during registration, which allows attackers to trick users into signing up using attacker-controlled email addresses via crafted invitation token.

CVE-2021-32004
GateManager General
3.7
LOW
EPSS
0.2%
2021 CWE-923 1 PoC

This issue affects: Secomea GateManager All versions prior to 9.6. Improper Check of host header in web server of Secomea GateManager allows attacker to cause browser cache poisoning.

CVE-2021-25367
Samsung Notes General
3.7
LOW
EPSS
0.2%
2021 CWE-22 2 PoCs

Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.

CVE-2021-37860
Mattermost General
3.7
LOW
EPSS
0.2%
2021 CWE-79 1 PoC

Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP.

CVE-2021-40340
Software Genérico General
3.7
LOW
EPSS
0.3%
2021 1 PoC

Information Exposure vulnerability in Hitachi Energy LinkOne application, due to a misconfiguration in the ASP server exposes server and ASP.net information, an attacker that manages to exploit this vulnerability can use the exposed information as a reconnaissance for further exploitation. This issue affects: Hitachi Energy LinkOne 3.20; 3.22; 3.23; 3.24; 3.25; 3.26.

CVE-2021-38939
QRadar SIEM General
3.7
LOW
EPSS
0.3%
2021 1 PoC

IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037.

CVE-2021-22174
Wireshark General
3.7
LOW
EPSS
0.2%
2021 1 PoC

Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file

CVE-2021-33596
F-Secure Mobile Security General
3.5
LOW
EPSS
0.3%
2021 1 PoC

Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. Exploiting the vulnerability requires the user to click on a specially crafted, seemingly legitimate URL containing an embedded malicious redirect while using F-Secure Safe Browser for iOS.

CVE-2021-21438
FAQ General
3.5
LOW
EPSS
0.2%
2021 CWE-264 1 PoC

Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ version 6.0.29 and prior versions, OTRS version 7.0.24 and prior versions.

CVE-2021-21436
OTRSCIsInCustomerFrontend General
3.5
LOW
EPSS
0.1%
2021 CWE-264 1 PoC

Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affects: OTRS AG OTRSCIsInCustomerFrontend 7.0.x version 7.0.14 and prior versions.

CVE-2021-37863
Mattermost General
3.5
LOW
EPSS
0.6%
2021 CWE-20 1 PoC

Mattermost 6.0 and earlier fails to sufficiently validate parameters during post creation, which allows authenticated attackers to cause a client-side crash of the web application via a maliciously crafted post.

CVE-2021-4250
active_attr General
3.5
LOW
EPSS
0.9%
2021 CWE-404 1 PoC

A vulnerability classified as problematic has been found in cgriego active_attr up to 0.15.2. This affects the function call of the file lib/active_attr/typecasting/boolean_typecaster.rb of the component Regex Handler. The manipulation of the argument value leads to denial of service. The exploit has been disclosed to the public and may be used. Upgrading to version 0.15.3 is able to address this issue. The name of the patch is dab95e5843b01525444b82bd7b336ef1d79377df. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216207.

CVE-2021-33572
F-Secure Products General
3.5
LOW
EPSS
0.4%
2021 CWE-476 1 PoC

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the FSAVD component used in certain F-Secure products can crash while scanning larger packages/fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus engine.

CVE-2021-21437
OTRSCIsInCustomerFrontend General
3.5
LOW
EPSS
0.1%
2021 CWE-264 1 PoC

Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects: OTRSCIsInCustomerFrontend 7.0.15 and prior versions, ITSMConfigurationManagement 7.0.24 and prior versions

CVE-2021-33595
F-Secure Mobile Security General
3.5
LOW
EPSS
0.3%
2021 1 PoC

A address bar spoofing vulnerability was discovered in Safe Browser for iOS. Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. A remote attacker can leverage this to perform address bar spoofing attack.

CVE-2021-33594
F-Secure Mobile Security General
3.5
LOW
EPSS
0.3%
2021 1 PoC

An address bar spoofing vulnerability was discovered in Safe Browser for Android. When user clicks on a specially crafted a malicious URL, it appears like a legitimate one on the address bar, while the content comes from other domain and presented in a window, covering the original content. A remote attacker can leverage this to perform address bar spoofing attack.

CVE-2021-4305
robots-txt-guard General
3.5
LOW
EPSS
0.5%
2021 CWE-1333 1 PoC

A vulnerability was found in Woorank robots-txt-guard. It has been rated as problematic. Affected by this issue is the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The name of the patch is c03827cd2f9933619c23894ce7c98401ea824020. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217448.