3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-34391
NVIDIA Jetson TX1 General
5.3
MEDIUM
EPSS
0.0%
2021 1 PoC

Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

CVE-2021-35578
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be explo

CVE-2021-22925
https://github.com/curl/curl Web
5.3
MEDIUM
EPSS
0.4%
2021 CWE-200 3 PoCs

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to theserver. Therefore potentially revealing sensitive internal information to theserver using a clear-text network protocol.This could happen because curl did not call and use sscanf() correctly whenparsing the string provided by the application.

CVE-2021-40404
Software Genérico Web
5.3
MEDIUM
EPSS
0.3%
2021 CWE-284 1 PoC

An authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2021-29099
ArcGIS Server Database
5.3
MEDIUM
EPSS
0.3%
2021 CWE-89 1 PoC

A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially crafted web requests can expose information that is not intended to be disclosed (not customer datasets). Web Services that use file based data sources (file Geodatabase or Shape Files or tile cached services) are unaffected by this issue.

CVE-2021-35556
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerab

CVE-2021-3820
pksunkara/inflect General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-1333 1 PoC

inflect is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-2297
VM VirtualBox Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base

CVE-2021-32640
ws Web
5.3
MEDIUM
EPSS
0.5%
2021 CWE-400 2 PoCs

ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.htm

CVE-2021-23343
path-parse General
5.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

CVE-2021-38915
Data Risk Manager General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Data Risk Manager 2.0.6 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 209947.

CVE-2021-35552
WebLogic Server Web Database
5.3
MEDIUM
EPSS
1.2%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Diagnostics). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).

CVE-2021-39211
glpi Web ⚡ nuclei
5.3
MEDIUM
EPSS
38.9%
2021 CWE-200 0 PoCs

GLPI is a free Asset and IT management software package. Starting in version 9.2 and prior to version 9.5.6, the telemetry endpoint discloses GLPI and server information. This issue is fixed in version 9.5.6. As a workaround, remove the file `ajax/telemetry.php`, which is not needed for usual functions of GLPI.

CVE-2021-36402
Moodle General
5.3
MEDIUM
EPSS
0.5%
2021 CWE-20 1 PoC

In Moodle, Users' names required additional sanitizing in the account confirmation email, to prevent a self-registration phishing risk.

CVE-2021-4433
Sami HTTP Server Web
5.3
MEDIUM
EPSS
0.1%
2021 CWE-404 2 PoCs

A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250836.

CVE-2021-25508
SmartThings Web
5.3
MEDIUM
EPSS
0.3%
2021 CWE-269 1 PoC

Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.

CVE-2021-42374
busybox General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-125 2 PoCs

An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that

CVE-2021-3647
medialize/URI.js General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-601 1 PoC

URI.js is vulnerable to URL Redirection to Untrusted Site

CVE-2021-2059
iStore Web Database
5.3
MEDIUM
EPSS
0.9%
2021 1 PoC

Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Web interface). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle iStore accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-4107
yetiforcecompany/yetiforcecrm Web
5.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')