3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-37861
Mattermost General
5.8
MEDIUM
EPSS
0.4%
2021 CWE-532 1 PoC

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

CVE-2021-40403
Gerbv General
5.8
MEDIUM
EPSS
0.2%
2021 CWE-456 1 PoC

An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-29490
jellyfin Web ⚡ nuclei
5.8
MEDIUM
EPSS
88.2%
2021 CWE-918 0 PoCs

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP `GET` that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints `/Items/*/RemoteImages/Download`, `/Items/RemoteSearch/Image` and `/Images/Remote`

CVE-2021-25380
Bixby General
5.8
MEDIUM
EPSS
0.3%
2021 CWE-703 2 PoCs

Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.

CVE-2021-21345
xstream General ⚡ nuclei
5.8
MEDIUM
EPSS
88.1%
2021 CWE-94 5 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-4043
gpac/gpac General
5.8
MEDIUM
EPSS
1.5%
2021 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

CVE-2021-35606
PeopleSoft Enterprise CS Campus Community Database
5.7
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framework). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS Campus Community executes to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community

CVE-2021-2445
Hyperion Infrastructure Technology Web Database
5.7
MEDIUM
EPSS
1.3%
2021 1 PoC

Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as unau

CVE-2021-36094
((OTRS)) Community Edition Web
5.7
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

CVE-2021-25507
Samsung Flow General
5.7
MEDIUM
EPSS
0.1%
2021 CWE-285 1 PoC

Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.

CVE-2021-25501
Samsung Mobile Devices Cloud
5.7
MEDIUM
EPSS
0.0%
2021 CWE-284 1 PoC

An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

CVE-2021-30496
Software Genérico General
5.7
MEDIUM
EPSS
0.6%
2021 1 PoC

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework. NOTE: the vendor's perspective is that "this behavior can't be considered a vulnerability."

CVE-2021-21435
OTRS General
5.7
MEDIUM
EPSS
0.3%
2021 CWE-200 1 PoC

Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.

CVE-2021-35494
TIBCO JasperReports Server Web Cloud
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contain a race condition that allows a low privileged authenticated attacker via the REST API to obtain read access to temporary objects created by other users on the affected system. Affected rel

CVE-2021-41355
PowerShell 7.1 General
5.7
MEDIUM
EPSS
3.6%
2021 1 PoC

.NET Core and Visual Studio Information Disclosure Vulnerability

CVE-2021-35601
PeopleSoft Enterprise CS SA Integration Pack Database
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Students Administration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS SA Integration Pack executes to compromise PeopleSoft Enterprise CS SA Integration Pack. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS SA Inte

CVE-2021-21337
Products.PluggableAuthService General
5.7
MEDIUM
EPSS
1.8%
2021 CWE-601 1 PoC

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the browser to a different website. The problem has been fixed in version 2.6.1. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to `2.6.1` and re-run the buildout, or if you used `pip` simply do `pip install "Products.PluggableAuthService>=2.6.1".

CVE-2021-45523
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

NETGEAR R7000 devices before 1.0.9.42 are affected by a buffer overflow by an authenticated user.

CVE-2021-3426
python General
5.7
MEDIUM
EPSS
0.1%
2021 CWE-200 2 PoCs

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVE-2021-25991
ifme General
5.7
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.