3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-22214
GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
93.3%
2021 7 PoCs

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVE-2021-46774
Ryzen™ 3000 series Desktop Processors “Matisse" General
6.7
MEDIUM
EPSS
0.0%
2021 3 PoCs

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

CVE-2021-30298
Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
6.7
MEDIUM
EPSS
0.0%
2021 1 PoC

Possible out of bound access due to improper validation of item size and DIAG memory pools data while switching between USB and PCIE interface in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2021-25396
Samsung Mobile Devices General
6.7
MEDIUM
EPSS
0.0%
2021 CWE-787 1 PoC

An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-47815
Nsauditor General
6.7
MEDIUM
EPSS
0.0%
2021 CWE-120 2 PoCs

Nsauditor 3.2.3 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can paste a large buffer of 256 repeated characters into the 'Key' field to trigger an application crash.

CVE-2021-47894
Managed Switch Port Mapping Tool General
6.7
MEDIUM
EPSS
0.0%
2021 CWE-770 1 PoC

Managed Switch Port Mapping Tool 2.85.2 contains a denial of service vulnerability that allows attackers to crash the application by creating an oversized buffer. Attackers can generate a 10,000-character buffer and paste it into the IP Address and SNMP Community Name fields to trigger the application crash.

CVE-2021-47877
GeoGebra Graphing Calculato‪r‬ DevOps
6.7
MEDIUM
EPSS
0.0%
2021 CWE-770 1 PoC

GeoGebra Graphing Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer. Attackers can generate a payload of 8000 repeated characters to overwhelm the input field and cause the application to become unresponsive.

CVE-2021-23877
McAfee Total Protection (MTP) Windows
6.7
MEDIUM
EPSS
0.0%
2021 CWE-269 1 PoC

Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.

CVE-2021-30263
Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music General
6.7
MEDIUM
EPSS
0.0%
2021 1 PoC

Possible race condition can occur due to lack of synchronization mechanism when On-Device Logging node open twice concurrently in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2021-1931
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music General
6.7
MEDIUM
EPSS
0.0%
2021 2 PoCs

Possible buffer overflow due to improper validation of buffer length while processing fast boot commands in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

CVE-2021-1958
Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables General
6.7
MEDIUM
EPSS
0.0%
2021 1 PoC

A race condition in fastrpc kernel driver for dynamic process creation can lead to use after free scenario in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile, Snapdragon Wearables

CVE-2021-2151
PeopleSoft Enterprise PT PeopleTools Web Database
6.7
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Security). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and

CVE-2021-47784
Cyberfox Web Browser General
6.7
MEDIUM
EPSS
0.0%
2021 CWE-770 1 PoC

Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application crash.

CVE-2021-30324
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
6.7
MEDIUM
EPSS
0.0%
2021 1 PoC

Possible out of bound write due to lack of boundary check for the maximum size of buffer when sending a DCI packet to remote process in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

CVE-2021-34382
NVIDIA Jetson TX1 General
6.7
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on the size parameter causes the request buffer and the logging buffer to overflow, allowing writes to arbitrary addresses within the kernel.

CVE-2021-47876
GeoGebra Classic General
6.7
MEDIUM
EPSS
0.0%
2021 CWE-770 1 PoC

GeoGebra Classic 5.0.631.0-d contains a denial of service vulnerability in the input field that allows attackers to crash the application by sending oversized buffer content. Attackers can generate a large buffer of 800,000 repeated characters and paste it into the 'Entrada:' input field to trigger an application crash.

CVE-2021-3972
Notebook BIOS General
6.7
MEDIUM
EPSS
3.2%
2021 CWE-489 1 PoC

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.

CVE-2021-3812
pi-hole/adminlte Web
6.7
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-47765
AbsoluteTelnet General
6.7
MEDIUM
EPSS
0.0%
2021 CWE-787 1 PoC

AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the username or email address fields, causing the application to become unresponsive.

CVE-2021-34381
NVIDIA Jetson TX1 General
6.7
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the size parameter of the tz_map_shared_mem function, which might lead to denial of service, information disclosure, or data tampering.