3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-26928
Software Genérico General
6.8
MEDIUM
EPSS
0.3%
2021 1 PoC

BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. NOTE: a researcher has asserted that the behavior is within Tigera’s area of responsibility; however, Tigera disagrees

CVE-2021-47789
Yenkee Hornet Gaming Mouse General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-121 2 PoCs

Yenkee Hornet Gaming Mouse driver GM312Fltr.sys contains a buffer overrun vulnerability that allows attackers to crash the system by sending oversized input. Attackers can exploit the driver by sending a 2000-byte buffer through DeviceIoControl to trigger a kernel-level system crash.

CVE-2021-2414
Communications Session Border Controller Web Database
6.8
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Routing). Supported versions that are affected are 8.4 and 9.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Session Border Controller. While the vulnerability is in Oracle Communications Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communi

CVE-2021-32633
Zope General
6.8
MEDIUM
EPSS
0.9%
2021 CWE-22 1 PoC

Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can add or edit Zope Page Templates through the web, but sites that allow untrusted users to add/edit Zope Page Templates through the web are at risk from this vulnerability. The problem has been fixed in Zope 5.2 and 4.6. As a workaround, a site administrator can restrict adding/editing Zope Page Templates through the web using the standard Zope user/role permis

CVE-2021-25362
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-269 2 PoCs

An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.

CVE-2021-21775
Webkit General
6.8
MEDIUM
EPSS
0.6%
2021 CWE-416 1 PoC

A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.

CVE-2021-3866
zulip/zulip Web
6.8
MEDIUM
EPSS
0.6%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

CVE-2021-47771
RDP Manager Windows
6.8
MEDIUM
EPSS
0.0%
2021 CWE-770 2 PoCs

RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attackers can add oversized entries in Verbindungsname and Server fields to permanently freeze and crash the software, potentially requiring full reinstallation.

CVE-2021-4188
mruby/mruby General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference

CVE-2021-22206
GitLab DevOps
6.8
MEDIUM
EPSS
0.1%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed that allows other maintainers to be able to view the credentials in plain-text,

CVE-2021-21569
NetWorker General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-78 1 PoC

Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

CVE-2021-3459
MM1000 MoCA Adapter General
6.8
MEDIUM
EPSS
0.1%
2021 CWE-78 1 PoC

A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.

CVE-2021-43991
Kentico Xperience XMS Web
6.8
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hij

CVE-2021-45607
Software Genérico General
6.8
MEDIUM
EPSS
0.3%
2021 1 PoC

Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects R6400v2 before 1.0.4.118, R6700v3 before 1.0.4.118, R6900P before 1.3.3.140, R7000 before 1.0.11.126, R7000P before 1.3.3.140, RAX200 before 1.0.5.126, RAX75 before 1.0.5.126, and RAX80 before 1.0.5.126.

CVE-2021-21570
NetWorker General
6.8
MEDIUM
EPSS
0.4%
2021 CWE-78 1 PoC

Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized information.

CVE-2021-29484
Ghost Web ⚡ nuclei
6.8
MEDIUM
EPSS
57.0%
2021 CWE-79 1 PoC

Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted users gaining access to Ghost Admin. Attackers can gain access by getting logged in users to click a link containing malicious code. Users do not need to enter credentials and may not know they've visited a malicious site. Ghost(Pro) has already been patched. We can find no evidence that the issue was exploited on Ghost(Pro) prior to the patch being added. Self-hosters are impacted if running Ghost a version between 4.0.0 and 4.3.2. Immediate action should be taken to secure

CVE-2021-21353
pug General
6.8
MEDIUM
EPSS
1.9%
2021 CWE-74 1 PoC

Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend. This is fixed in version 3.0.1. This advisory applies to multiple pug packages including "pug", "pug-code-gen". pug-code-gen has a backported fix at version 2.0.3. This advisory is not exploitable if there is no way for un-

CVE-2021-4187
vim/vim General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-25363
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-269 2 PoCs

An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.

CVE-2021-35567
Java SE JDK and JRE Database Windows
6.8
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional pr