3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-34380
NVIDIA Jetson TX1, TX2 series, TX2 NX, AGX Xavier series, Xavier NX, Nano and Nano 2GB General
7.0
HIGH
EPSS
0.1%
2021 1 PoC

Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

CVE-2021-1099
NVIDIA Virtual GPU Software General
7.0
HIGH
EPSS
0.2%
2021 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-2454
VM VirtualBox Database
7.0
HIGH
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.24. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVE-2021-33632
iSulad Web
7.0
HIGH
EPSS
0.0%
2021 CWE-367 1 PoC

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad/main.C. This issue affects iSulad: 2.0.18-13, from 2.1.4-1 through 2.1.4-2.

CVE-2021-1120
NVIDIA Virtual GPU Software General
7.0
HIGH
EPSS
0.0%
2021 CWE-170 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead to information disclosure, data tampering, unauthorized code execution, and denial of service.

CVE-2021-47785
Ether_MP3_CD_Burner General
7.0
HIGH
EPSS
0.1%
2021 CWE-787 1 PoC

Ether MP3 CD Burner 1.3.8 contains a buffer overflow vulnerability in the registration name field that allows remote code execution. Attackers can craft a malicious payload to overwrite SEH handlers and execute a bind shell on port 3110 by exploiting improper input validation.

CVE-2021-47740
JT3500V General
6.9
MEDIUM
EPSS
0.1%
2021 CWE-613 1 PoC

KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access and potentially compromise device authentication mechanisms.

CVE-2021-47715
Hasura GraphQL General
6.9
MEDIUM
EPSS
0.1%
2021 CWE-918 1 PoC

Hasura GraphQL 1.3.3 contains a server-side request forgery vulnerability that allows attackers to inject arbitrary remote schema URLs through the add_remote_schema endpoint. Attackers can exploit the vulnerability by sending crafted POST requests to the /v1/query endpoint with malicious URL definitions to potentially access internal network resources.

CVE-2021-41174
grafana DevOps Web ⚡ nuclei
6.9
MEDIUM
EPSS
87.7%
2021 CWE-79 0 PoCs

Grafana is an open-source platform for monitoring and observability. In affected versions if an attacker is able to convince a victim to visit a URL referencing a vulnerable page, arbitrary JavaScript content may be executed within the context of the victim's browser. The user visiting the malicious link must be unauthenticated and the link must be for a page that contains the login button in the menu bar. The url has to be crafted to exploit AngularJS rendering and contain the interpolation binding for AngularJS expressions. AngularJS uses double curly braces for interpolation binding: {{ }}

CVE-2021-47714
Hasura GraphQL Database
6.9
MEDIUM
EPSS
0.0%
2021 CWE-89 1 PoC

Hasura GraphQL 1.3.3 contains a local file read vulnerability that allows attackers to access system files through SQL injection in the query endpoint. Attackers can exploit the pg_read_file() PostgreSQL function by crafting malicious SQL queries to read arbitrary files on the server.

CVE-2021-47899
YetiShare File Hosting Script General
6.9
MEDIUM
EPSS
0.1%
2021 CWE-434 1 PoC

YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:/// protocol.

CVE-2021-47754
Arunna Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

Arunna 1.0.0 contains a cross-site request forgery vulnerability that allows attackers to manipulate user profile settings without authentication. Attackers can craft a malicious form to change user details, including passwords, email, and administrative privileges by tricking authenticated users into submitting the form.

CVE-2021-47776
Umbraco Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-918 1 PoC

Umbraco CMS v8.14.1 contains a server-side request forgery vulnerability that allows attackers to manipulate baseUrl parameters in multiple dashboard and help controller endpoints. Attackers can craft malicious requests to the GetContextHelpForPage, GetRemoteDashboardContent, and GetRemoteDashboardCss endpoints to trigger unauthorized server-side requests to external hosts.

CVE-2021-45516
Software Genérico General
6.9
MEDIUM
EPSS
0.0%
2021 1 PoC

Certain NETGEAR devices are affected by denial of service. This affects R6400 before 1.0.1.70, R7000 before 1.0.11.126, R6900P before 1.3.3.140, R7000P before 1.3.3.140, R8000 before 1.0.4.74, RBK852 before 3.2.10.11, RBR850 before 3.2.10.11, and RBS850 before 3.2.10.11.

CVE-2021-38523
Software Genérico General
6.9
MEDIUM
EPSS
0.7%
2021 1 PoC

NETGEAR R6400 devices before 1.0.1.70 are affected by a stack-based buffer overflow by an authenticated user.

CVE-2021-47717
IntelliChoice eFORCE Software Suite General
6.9
MEDIUM
EPSS
0.1%
2021 CWE-204 2 PoCs

IntelliChoice eFORCE Software Suite 2.5.9 contains a username enumeration vulnerability that allows attackers to enumerate valid users by exploiting the 'ctl00$MainContent$UserName' POST parameter. Attackers can send requests with valid usernames to retrieve user information.

CVE-2021-47703
OpenBMCS Web Networking
6.9
MEDIUM
EPSS
0.1%
2021 CWE-918 2 PoCs

OpenBMCS 2.4 contains an unauthenticated SSRF vulnerability that allows attackers to bypass firewalls and initiate service and network enumeration on the internal network through the affected application, allowing hijacking of current sessions. Attackers can specify an external domain in the 'ip' parameter to force the application to make an HTTP request to an arbitrary destination host.

CVE-2021-47723
STVS ProVision Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 2 PoCs

STVS ProVision 5.9.10 contains a cross-site request forgery vulnerability that allows attackers to perform actions with administrative privileges by exploiting unvalidated HTTP requests. Attackers can visit malicious web sites to trigger the forge request, allowing them to create new admin users.

CVE-2021-47712
Xperience General
6.9
MEDIUM
EPSS
0.0%
2021 CWE-327 1 PoC

A cryptography vulnerability in Kentico Xperience allows attackers to potentially manipulate URL hash values through existing hashing mechanisms. The hotfix introduces an additional security layer to prevent hash value reuse and potential exploitation.

CVE-2021-47800
b2evolution Web
6.9
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

b2evolution 7.2.2 contains a cross-site request forgery vulnerability that allows attackers to modify admin account details without authentication. Attackers can craft a malicious HTML form to submit unauthorized changes to user profiles by tricking victims into loading a specially crafted webpage.