3376 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2021-25376
Samsung Email General
3.1
LOW
EPSS
0.2%
2021 CWE-200 2 PoCs

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.

CVE-2021-32618
flask-security General ⚡ nuclei
3.1
LOW
EPSS
17.1%
2021 CWE-601 0 PoCs

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-Security-Too allow redirects after many successful views (e.g. /login) by honoring the ?next query param. There is code in FS to validate that the url specified in the next parameter is either relative OR has the same netloc (network location) as the requesting URL. This check utilizes Pythons urlsplit library. However many browsers are very lenient on the kin

CVE-2021-34396
NVIDIA Jetson TX2 series, TX2 NX General
3.0
LOW
EPSS
0.1%
2021 1 PoC

Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.

CVE-2021-34428
Eclipse Jetty General
2.9
LOW
EPSS
0.3%
2021 CWE-613 4 PoCs

For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.

CVE-2021-25336
Samsung Mobile Devices General
2.8
LOW
EPSS
0.0%
2021 CWE-269 2 PoCs

Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.

CVE-2021-34685
Software Genérico General
2.7
LOW
EPSS
2.0%
2021 1 PoC

UploadService in Hitachi Vantara Pentaho Business Analytics through 9.1 does not properly verify uploaded user files, which allows an authenticated user to upload various files of different file types. Specifically, a .jsp file is not allowed, but a .jsp. file is allowed (and leads to remote code execution).

CVE-2021-20508
Security Secret Server General
2.7
LOW
EPSS
0.1%
2021 1 PoC

IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322.

CVE-2021-25939
arangodb General
2.7
LOW
EPSS
0.2%
2021 CWE-918 1 PoC

In ArangoDB, versions v3.7.0 through v3.9.0-alpha.1 have a feature which allows downloading a Foxx service from a publicly available URL. This feature does not enforce proper filtering of requests performed internally, which can be abused by a highly-privileged attacker to perform blind SSRF and send internal requests to localhost.

CVE-2021-46270
JFrog Artifactory General
2.7
LOW
EPSS
0.2%
2021 CWE-284 1 PoC

JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all available repository names due to insufficient permission validation.

CVE-2021-28163
Eclipse Jetty General
2.7
LOW
EPSS
0.2%
2021 CWE-200 3 PoCs

In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.

CVE-2021-36382
Software Genérico General
2.6
LOW
EPSS
0.1%
2021 1 PoC

Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).

CVE-2021-25486
Samsung Mobile Devices General
2.5
LOW
EPSS
0.0%
2021 CWE-200 1 PoC

Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.

CVE-2021-25335
Samsung Mobile Devices General
2.5
LOW
EPSS
0.0%
2021 CWE-703 2 PoCs

Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.

CVE-2021-46766
Ryzen™ Threadripper™ PRO 3000WX Series Processors “Chagall” WS General
2.5
LOW
EPSS
0.0%
2021 3 PoCs

Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.

CVE-2021-38514
Software Genérico General
2.4
LOW
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by authentication bypass. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6100 before 1.0.0.63, D6200 before 1.1.00.34, D6220 before 1.0.0.48, D6400 before 1.0.0.86, D7000 before 1.0.1.70, D7000v2 before 1.0.0.52, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before 1.0.0.108, DGND2200Bv4 before 1.0.0.108, EX2700 before 1.0.1.48, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6000 before 1.0.0.38, EX6100 before 1.0.2.24, EX6100v2 before 1.0.1.76, EX6120 before 1.0.0.42, EX6130 before 1.0.0.28, EX6150v1 before

CVE-2021-25513
Samsung Mobile Devices General
2.4
LOW
EPSS
0.0%
2021 CWE-269 1 PoC

An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.

CVE-2021-25491
Samsung Mobile Devices General
2.3
LOW
EPSS
0.0%
2021 CWE-476 1 PoC

A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.

CVE-2021-25389
Samsung Mobile Devices General
2.3
LOW
EPSS
0.0%
2021 CWE-287 1 PoC

Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

CVE-2021-41527
RISC Platform General
2.3
LOW
EPSS
0.1%
2021 1 PoC

An error related to the 2-factor authorization (2FA) on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to bypass the 2FA. The vulnerability requires that the 2FA setup hasn’t been completed.

CVE-2021-25348
Samsung Internet General
2.1
LOW
EPSS
0.1%
2021 CWE-703 2 PoCs

Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.