3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-23760
Software Genérico Web
5.6
MEDIUM
EPSS
2.4%
2021 2 PoCs

The package keyget from 0.0.0 are vulnerable to Prototype Pollution via the methods set, push, and at which could allow an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-28272](https://security.snyk.io/vuln/SNYK-JS-KEYGET-1048048)

CVE-2021-23444
jointjs General
5.6
MEDIUM
EPSS
1.5%
2021 3 PoCs

This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.

CVE-2021-23380
roar-pidusage General
5.6
MEDIUM
EPSS
0.5%
2021 1 PoC

This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-23820
json-pointer General
5.6
MEDIUM
EPSS
0.5%
2021 2 PoCs

This affects all versions of package json-pointer. A type confusion vulnerability can lead to a bypass of CVE-2020-7709 when the pointer components are arrays.

CVE-2021-25456
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf file.

CVE-2021-2304
MySQL Server Database
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impac

CVE-2021-3863
snipe/snipe-it Web
5.5
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-34564
WHA-GW-F2D2-0-AS- Z2-ETH Networking
5.5
MEDIUM
EPSS
0.0%
2021 CWE-315 1 PoC

Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.

CVE-2021-25373
Customization Service General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

CVE-2021-25488
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.

CVE-2021-26343
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.

CVE-2021-35612
MySQL Server Database
5.5
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CV

CVE-2021-1699
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows (modem.sys) Information Disclosure Vulnerability

CVE-2021-42375
busybox General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-159 2 PoCs

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.

CVE-2021-33602
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Cloud Protection for Salesforce Cloud Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

CVE-2021-25452
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-22 1 PoC

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.

CVE-2021-46791
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binary to corrupt Dynamic Root of Trust for Measurement (DRTM) user application memory that may result in a potential denial of service.

CVE-2021-4193
vim/vim General
5.5
MEDIUM
EPSS
0.6%
2021 CWE-125 1 PoC

vim is vulnerable to Out-of-bounds Read

CVE-2021-47631
Linux General
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

In the Linux kernel, the following vulnerability has been resolved: ARM: davinci: da850-evm: Avoid NULL pointer dereference With newer versions of GCC, there is a panic in da850_evm_config_emac() when booting multi_v5_defconfig in QEMU under the palmetto-bmc machine: Unable to handle kernel NULL pointer dereference at virtual address 00000020 pgd = (ptrval) [00000020] *pgd=00000000 Internal error: Oops: 5 [#1] PREEMPT ARM Modules linked in: CPU: 0 PID: 1 Comm: swapper Not tainted 5.15.0 #1 Hardware name: Generic DT based system PC is at da850_evm_config_emac+0x1c/0x120 LR is at do_one_initc

CVE-2021-26404
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.