3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-22142
Kibana General
6.6
MEDIUM
EPSS
0.5%
2021 CWE-1104 1 PoC

Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable reports. If a user with permissions to generate reports is able to render arbitrary HTML with this browser, they may be able to leverage known Chromium vulnerabilities to conduct further attacks. Kibana contains a number of protections to prevent this browser from rendering arbitrary content.

CVE-2021-4179
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-4116
yetiforcecompany/yetiforcecrm Web
6.6
MEDIUM
EPSS
0.1%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-25393
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.0%
2021 CWE-94 2 PoCs

Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.

CVE-2021-4175
livehelperchat/livehelperchat Web
6.6
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-45515
Software Genérico General
6.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Certain NETGEAR devices are affected by denial of service. This affects EX7500 before 1.0.0.72, RBS40V before 2.6.1.4, RBW30 before 2.6.1.4, RBRE960 before 6.0.3.68, RBSE960 before 6.0.3.68, RBR750 before 3.2.17.12, RBR850 before 3.2.17.12, RBS750 before 3.2.17.12, RBS850 before 3.2.17.12, RBK752 before 3.2.17.12, and RBK852 before 3.2.17.12.

CVE-2021-21439
((OTRS)) Community Edition General
6.5
MEDIUM
EPSS
0.3%
2021 CWE-754 1 PoC

DoS attack can be performed when an email contains specially designed URL in the body. It can lead to the high CPU usage and cause low quality of service, or in extreme case bring the system to a halt. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.26 and prior versions; 8.0.x version 8.0.13 and prior versions.

CVE-2021-4472
Red Hat OpenStack Platform 13 (Queens) General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-73 1 PoC

The mistral-dashboard plugin for openstack has a local file inclusion vulnerability through the 'Create Workbook' feature that may result in disclosure of arbitrary local files content.

CVE-2021-41349
Microsoft Exchange Server 2013 Cumulative Update 23 Windows ⚡ nuclei
6.5
MEDIUM
EPSS
91.1%
2021 2 PoCs

Microsoft Exchange Server Spoofing Vulnerability

CVE-2021-39369
Software Genérico General
6.5
MEDIUM
EPSS
0.4%
2021 1 PoC

In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.

CVE-2021-37499
Software Genérico Web
6.5
MEDIUM
EPSS
0.3%
2021 1 PoC

CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View License Result function, that allows remote attackers to inject arbitrary HTTP headers.

CVE-2021-4131
livehelperchat/livehelperchat Web
6.5
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-26947
Odoo Community Web ⚡ nuclei
6.5
MEDIUM
EPSS
59.3%
2021 CWE-79 0 PoCs

Cross-site scripting (XSS) issue Odoo Community 15.0 and earlier and Odoo Enterprise 15.0 and earlier, allows remote attackers to inject arbitrary web script in the browser of a victim, via a crafted link.

CVE-2021-3734
yourls/yourls General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-1021 1 PoC

yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames

CVE-2021-4033
kevinpapst/kimai2 Web
6.5
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-45495
Software Genérico General
6.5
MEDIUM
EPSS
0.3%
2021 1 PoC

NETGEAR D7000 devices before 1.0.1.68 are affected by authentication bypass.

CVE-2021-31867
Pimcore Customer Data Framework Web Database
6.5
MEDIUM
EPSS
0.0%
2021 CWE-89 1 PoC

Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the $id parameter of the SegmentAssignmentController.php component of the application. This issue was fixed in version 3.0.2 of the product.

CVE-2021-41788
Software Genérico General
6.5
MEDIUM
EPSS
0.5%
2021 1 PoC

MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

CVE-2021-26403
1st Gen EPYC General
6.5
MEDIUM
EPSS
0.0%
2021 1 PoC

Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.

CVE-2021-3730
firefly-iii/firefly-iii Web
6.5
MEDIUM
EPSS
0.1%
2021 CWE-352 1 PoC

firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)