3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-38532
Software Genérico General
6.8
MEDIUM
EPSS
0.5%
2021 1 PoC

NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.

CVE-2021-21327
glpi General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-862 1 PoC

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to carry out malicious attacks, or to start a “POP chain”. As an example of direct impact, this vulnerability affects integrity of the GLPI core platform and third-party plugins runtime misusing classes which implement some sensitive operations in their constructors or destructors. This is fixed in versio

CVE-2021-25397
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

CVE-2021-21779
Webkit General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-416 1 PoC

A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability.

CVE-2021-1895
Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music General
6.8
MEDIUM
EPSS
0.0%
2021 1 PoC

Possible integer overflow due to improper length check while flashing an image in Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music

CVE-2021-3879
snipe/snipe-it Web
6.8
MEDIUM
EPSS
0.5%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-47759
MTPutty Networking Windows
6.8
MEDIUM
EPSS
0.0%
2021 CWE-522 1 PoC

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes, exposing plaintext SSH credentials.

CVE-2021-2046
MySQL Server Database
6.8
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.8 (Availability impacts). CVSS Ve

CVE-2021-46775
2nd Gen AMD EPYC™ General
6.8
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.

CVE-2021-22175
🔥 KEV GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
69.7%
2021 1 PoC

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVE-2021-31505
Q Plus Networking
6.8
MEDIUM
EPSS
0.3%
2021 CWE-798 1 PoC

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.

CVE-2021-4173
vim/vim General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-22238
GitLab DevOps Web
6.8
MEDIUM
EPSS
1.2%
2021 1 PoC

An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

CVE-2021-4103
vanessa219/vditor Web
6.8
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository vanessa219/vditor prior to 1.0.34.

CVE-2021-37577
Software Genérico General
6.8
MEDIUM
EPSS
0.0%
2021 1 PoC

Bluetooth LE and BR/EDR Secure Connections pairing and Secure Simple Pairing using the Passkey entry protocol in Bluetooth Core Specifications 2.1 through 5.3 may permit an unauthenticated man-in-the-middle attacker to identify the Passkey used during pairing by reflection of a crafted public key with the same X coordinate as the offered public key and by reflection of the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. This is a related issue t

CVE-2021-34480
Windows 10 Version 1809 Windows
6.8
MEDIUM
EPSS
3.1%
2021 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2021-47786
Redragon Gaming Mouse General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-787 2 PoCs

Redragon Gaming Mouse driver contains a kernel-level vulnerability that allows attackers to trigger a denial of service by sending malformed IOCTL requests. Attackers can send a crafted 2000-byte buffer with specific byte patterns to the REDRAGON_MOUSE device to crash the kernel driver.

CVE-2021-38522
Software Genérico General
6.8
MEDIUM
EPSS
0.5%
2021 1 PoC

NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.

CVE-2021-3645
viking04/merge General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-1321 1 PoC

merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')