2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-39877
GitLab DevOps
7.7
HIGH
EPSS
0.2%
2021 1 PoC

A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

CVE-2021-21921
Advantech Web Database
7.7
HIGH
EPSS
1.3%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘name_filter’ parameter with the administrative account or through cross-site request forgery.

CVE-2021-21234
spring-boot-actuator-logview Web ⚡ nuclei
7.7
HIGH
EPSS
93.9%
2021 CWE-22 2 PoCs

spring-boot-actuator-logview in a library that adds a simple logfile viewer as spring boot actuator endpoint. It is maven package "eu.hinsch:spring-boot-actuator-logview". In spring-boot-actuator-logview before version 0.2.13 there is a directory traversal vulnerability. The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request parameters. While the filename parameter was checked to prevent directory traversal exploits (so that `file

CVE-2021-34378
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to information disclosure, denial of service, or escalation of privileges.

CVE-2021-21287
minio Web ⚡ nuclei
7.7
HIGH
EPSS
91.7%
2021 CWE-918 0 PoCs

MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-30T00-20-58Z there is a server-side request forgery vulnerability. The target application may have functionality for importing data from a URL, publishing data to a URL, or otherwise reading data from a URL that can be tampered with. The attacker modifies the calls to this functionality by supplying a completely different URL or by manipulating how URLs are built (path traversal etc.). In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the

CVE-2021-34379
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
7.7
HIGH
EPSS
0.1%
2021 1 PoC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.

CVE-2021-21930
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-21380
xwiki-platform Web Database
7.7
HIGH
EPSS
3.3%
2021 CWE-89 1 PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL requests without escaping the from and where search arguments. This might lead to an SQL script injection quite easily for any user having Script rights on XWiki. The problem has been patched in XWiki 12.9RC1. The only workaround besides upgrading XWiki would be to uninstall the Ratings API in XWiki from the Extension Manager.

CVE-2021-21937
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_alt_filter’ parameter. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-45447
Pentaho Business Analytics Server General
7.7
HIGH
EPSS
0.1%
2021 CWE-319 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage feature enabled transmits database passwords in clear text.   The transmission of sensitive data in clear text allows unauthorized actors with access to the network to sniff and obtain sensitive information that can be later used to gain unauthorized access.

CVE-2021-21917
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at '‘ord’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-25517
Samsung Mobile Devices General
7.7
HIGH
EPSS
0.0%
2021 CWE-20 1 PoC

An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.

CVE-2021-21915
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

An exploitable SQL injection vulnerability exist in the ‘group_list’ page of the Advantech R-SeeNet 2.4.15 (30.07.2021). A specially-crafted HTTP request at ‘company_filter’ parameter. An attacker can make authenticated HTTP requests to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-35653
Hyperion Essbase Administration Services Web Database
7.7
HIGH
EPSS
0.4%
2021 1 PoC

Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Essbase Administration Services. While the vulnerability is in Essbase Administration Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Essbase Administration Services ac

CVE-2021-21924
Advantech Web Database
7.7
HIGH
EPSS
1.4%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘desc_filter’ parameter.

CVE-2021-21928
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-21925
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger these vulnerabilities. This can be done as any authenticated user or through cross-site request forgery at ‘firm_filter’ parameter.

CVE-2021-21929
Advantech Web Database
7.7
HIGH
EPSS
1.2%
2021 CWE-89 1 PoC

A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger this vulnerability. This can be done as any authenticated user or through cross-site request forgery.

CVE-2021-23420
codeception/codeception General
7.7
HIGH
EPSS
0.6%
2021 1 PoC

This affects the package codeception/codeception from 4.0.0 and before 4.1.22, before 3.1.3. The RunProcess class can be leveraged as a gadget to run arbitrary commands on a system that is deserializing user input without validation.

CVE-2021-23592
topthink/framework General
7.7
HIGH
EPSS
1.0%
2021 1 PoC

The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unserialize method in the Driver class.