3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-35221
Orion Platform General
6.3
MEDIUM
EPSS
0.4%
2021 CWE-284 1 PoC

Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

CVE-2021-35593
MySQL Cluster Database
6.3
MEDIUM
EPSS
39.3%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3

CVE-2021-21473
SAP NetWeaver AS ABAP and ABAP Platform (SRM_RFC_SUBMIT_REPORT) General
6.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

SAP NetWeaver AS ABAP and ABAP Platform, versions - 700, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, contains function module SRM_RFC_SUBMIT_REPORT which fails to validate authorization of an authenticated user thus allowing an unauthorized user to execute reports in SAP NetWeaver ABAP Platform.

CVE-2021-23348
portprocesses General
6.3
MEDIUM
EPSS
1.1%
2021 1 PoC

This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-41091
moby DevOps
6.3
MEDIUM
EPSS
4.7%
2021 CWE-281 2 PoCs

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When containers included executable programs with extended permission bits (such as `setuid`), unprivileged Linux users could discover and execute those programs. When the UID of an unprivileged Linux user on the host collided with the file owner or gro

CVE-2021-35598
MySQL Cluster Database
6.3
MEDIUM
EPSS
39.3%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3

CVE-2021-38539
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.10, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

CVE-2021-3904
getgrav/grav Web
6.3
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-35592
MySQL Cluster Database
6.3
MEDIUM
EPSS
28.6%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality,

CVE-2021-27909
Mautic Web ⚡ nuclei
6.3
MEDIUM
EPSS
18.7%
2021 CWE-79 0 PoCs

For Mautic versions prior to 3.3.4/4.0.0, there is an XSS vulnerability on Mautic's password reset page where a vulnerable parameter, "bundle," in the URL could allow an attacker to execute Javascript code. The attacker would be required to convince or trick the target into clicking a password reset URL with the vulnerable parameter utilized.

CVE-2021-23327
apexcharts Web
6.3
MEDIUM
EPSS
0.3%
2021 2 PoCs

The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.

CVE-2021-34385
NVIDIA Jetson TX1 General
6.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length could lead to a heap overflow.

CVE-2021-4018
snipe/snipe-it Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-29449
pi-hole General
6.3
MEDIUM
EPSS
11.4%
2021 CWE-269 1 PoC

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

CVE-2021-38615
Software Genérico General
6.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information.

CVE-2021-1906
🔥 KEV Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
6.2
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper handling of address deregistration on failure can lead to new GPU address allocation failure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2021-25344
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2021 2 PoCs

Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.

CVE-2021-32821
mootools-core Web
6.2
MEDIUM
EPSS
0.2%
2021 CWE-400 1 PoC

MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.

CVE-2021-1093
NVIDIA GPU Display Driver Windows
6.2
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.

CVE-2021-3756
hoene/libmysofa General
6.2
MEDIUM
EPSS
0.3%
2021 CWE-122 1 PoC

libmysofa is vulnerable to Heap-based Buffer Overflow