3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3765
validatorjs/validator.js General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-1333 1 PoC

validator.js is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-25522
Samsung Capture General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.

CVE-2021-36093
((OTRS)) Community Edition General
5.3
MEDIUM
EPSS
0.5%
2021 CWE-185 1 PoC

It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

CVE-2021-4432
FTP Server General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-404 3 PoCs

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as problematic. This affects an unknown part of the component USER Command Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250719.

CVE-2021-21275
Report Web
5.3
MEDIUM
EPSS
0.2%
2021 CWE-352 2 PoCs

The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of MediaWiki edit tokens.

CVE-2021-2163
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vul

CVE-2021-25347
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-287 2 PoCs

Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to intercept when the provider is executed.

CVE-2021-25510
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

CVE-2021-20995
0852-0303 General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-312 1 PoC

In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.

CVE-2021-31602
Software Genérico Web ⚡ nuclei
5.3
MEDIUM
EPSS
92.8%
2021 1 PoC

An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The Security Model has different layers of Access Control. One of these layers is the applicationContext security, which is defined in the applicationContext-spring-security.xml file. The default configuration allows an unauthenticated user with no previous knowledge of the platform settings to extract pieces of information without possessing valid credentials.

CVE-2021-41160
FreeRDP Web Windows
5.3
MEDIUM
EPSS
0.1%
2021 CWE-787 1 PoC

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a malicious server might trigger out of bound writes in a connected client. Connections using GDI or SurfaceCommands to send graphics updates to the client might send `0` width/height or out of bound rectangles to trigger out of bound writes. With `0` width or heigth the memory allocation will be `0` but the missing bounds checks allow writing to the pointer at this (not allocated) region. This issue has been patched in FreeRDP 2.4.1.

CVE-2021-21000
Series PFC200 Controller General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-770 1 PoC

On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.

CVE-2021-2296
VM VirtualBox Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base

CVE-2021-27659
exacqVision Web Service General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2021-41528
RISC Platform General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-863 1 PoC

An error when handling authorization related to the import / export interfaces on the RISC Platform prior to the saas-2021-12-29 release can potentially be exploited to access the import / export functionality with low privileges.

CVE-2021-21342
xstream General
5.3
MEDIUM
EPSS
0.9%
2021 CWE-502 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the processed input stream and replace or inject objects, that result in a server-side forgery request. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If

CVE-2021-34390
NVIDIA Jetson TX1 General
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

CVE-2021-2204
WebLogic Server Web Database
5.3
MEDIUM
EPSS
1.4%
2021 1 PoC

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-47953
OpenCart Web
5.3
MEDIUM
EPSS
0.0%
2021 CWE-352 1 PoC

OpenCart 3.0.3.7 contains a cross-site request forgery vulnerability that allows attackers to change user passwords by sending crafted requests to the account/password endpoint. Attackers can trick authenticated users into submitting hidden forms with new password values in the 'password' and 'confirm' parameters to hijack accounts.

CVE-2021-36805
Akaunting Web
5.2
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

Akaunting version 2.1.12 and earlier suffers from a persistent (type II) cross-site scripting (XSS) vulnerability in the sales invoice processing component of the application. This issue was fixed in version 2.1.13 of the product.