3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-40186
DNN Platform Web Networking Cloud
6.5
MEDIUM
EPSS
0.3%
2021 CWE-918 1 PoC

The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services.

CVE-2021-41183
jquery-ui General
6.5
MEDIUM
EPSS
2.9%
2021 CWE-79 5 PoCs

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is to not accept the value of the `*Text` options from untrusted sources.

CVE-2021-22570
Protobuf General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

CVE-2021-25973
publify_core General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-285 1 PoC

In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.

CVE-2021-32005
SiteManager Web
6.5
MEDIUM
EPSS
0.5%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in log view of Secomea SiteManager allows a logged in user to store javascript for later execution. This issue affects: Secomea SiteManager Version 9.6.621421014 and all prior versions.

CVE-2021-36329
Dell EMC Streaming Data Platform General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-639 1 PoC

Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. A remote malicious user may potentially exploit this vulnerability to gain sensitive information.

CVE-2021-31882
Capital Embedded AR Classic 431-422 Web
6.5
MEDIUM
EPSS
1.4%
2021 CWE-119 1 PoC

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to Denial-of-Service conditions. (FSMD-2021-0011)

CVE-2021-23663
sey General
6.5
MEDIUM
EPSS
0.5%
2021 1 PoC

All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

CVE-2021-23561
comb General
6.5
MEDIUM
EPSS
0.5%
2021 1 PoC

All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.

CVE-2021-21967
SeaConnect 370W General
6.5
MEDIUM
EPSS
0.3%
2021 CWE-120 1 PoC

An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.

CVE-2021-2294
WebLogic Server Database
6.5
MEDIUM
EPSS
1.4%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.1

CVE-2021-45608
Software Genérico General
6.5
MEDIUM
EPSS
5.0%
2021 2 PoCs

Certain D-Link, Edimax, NETGEAR, TP-Link, Tenda, and Western Digital devices are affected by an integer overflow by an unauthenticated attacker. Remote code execution from the WAN interface (TCP port 20005) cannot be ruled out; however, exploitability was judged to be of "rather significant complexity" but not "impossible." The overflow is in SoftwareBus_dispatchNormalEPMsgOut in the KCodes NetUSB kernel module. Affected NETGEAR devices are D7800 before 1.0.1.68, R6400v2 before 1.0.4.122, and R6700v3 before 1.0.4.122.

CVE-2021-1960
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
6.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper handling of ASB-C broadcast packets with crafted opcode in LMP can lead to uncontrolled resource consumption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2021-21791
IOBit General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-782 1 PoC

An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read two bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.

CVE-2021-21816
D-LINK Web ⚡ nuclei
6.5
MEDIUM
EPSS
77.3%
2021 CWE-200 1 PoC

An information disclosure vulnerability exists in the Syslog functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to the disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-4377
Doneren met Mollie Web Windows
6.5
MEDIUM
EPSS
0.4%
2021 CWE-200 1 PoC

The Doneren met Mollie plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.8.5 via the dmm_export_donations() function which is called via the admin_post_dmm_export hook due to missing capability checks. This can allow authenticated attackers to extract a CSV file that contains sensitive information about the donors.

CVE-2021-3916
bookstackapp/bookstack General
6.5
MEDIUM
EPSS
0.4%
2021 CWE-22 1 PoC

bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVE-2021-3992
kevinpapst/kimai2 General
6.5
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

kimai2 is vulnerable to Improper Access Control

CVE-2021-21792
IObit General
6.5
MEDIUM
EPSS
0.1%
2021 CWE-782 1 PoC

An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handles Privileged I/O read requests. A specially crafted I/O request packet (IRP) can lead to privileged reads in the context of a driver which can result in sensitive information disclosure from the kernel. The IN instruction can read four bytes from the given I/O device, potentially leaking sensitive device data to unprivileged users.

CVE-2021-2421
PeopleSoft Enterprise CS Campus Community Web Database
6.5
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR