2106 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-36320
Networking X-Series General
7.5
HIGH
EPSS
0.8%
2021 CWE-331 1 PoC

Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID.

CVE-2021-23460
min-dash General
7.5
HIGH
EPSS
0.5%
2021 2 PoCs

The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of key types.

CVE-2021-35065
Software Genérico General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

CVE-2021-2189
Sales Offline Web Database
7.5
HIGH
EPSS
1.6%
2021 1 PoC

Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Template). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Sales Offline. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2021-23772
github.com/kataras/iris General
7.5
HIGH
EPSS
0.9%
2021 2 PoCs

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

CVE-2021-43859
xstream General
7.5
HIGH
EPSS
1.9%
2021 CWE-400 2 PoCs

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. Se

CVE-2021-43444
Software Genérico General
7.5
HIGH
EPSS
1.5%
2021 1 PoC

ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be forged due to a weak default URL signing key.

CVE-2021-34561
WHA-GW-F2D2-0-AS- Z2-ETH Networking
7.5
HIGH
EPSS
0.3%
2021 CWE-350 1 PoC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 serious issue exists, if the application is not externally accessible or uses IP-based access restrictions. Attackers can use DNS Rebinding to bypass any IP or firewall based access restrictions that may be in place, by proxying through their target's browser.

CVE-2021-3757
immerjs/immer General
7.5
HIGH
EPSS
0.6%
2021 CWE-1321 1 PoC

immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-36369
Software Genérico Networking
7.5
HIGH
EPSS
0.2%
2021 1 PoC

An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.

CVE-2021-29486
cumulative-distribution-function General
7.5
HIGH
EPSS
0.7%
2021 CWE-20 1 PoC

cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution function from data array of x values. In versions prior to 2.0.0 apps using this library on improper data may crash or go into an infinite-loop. In the case of a nodejs server-app using this library to act on invalid non-numeric data, the nodejs server may crash. This may affect other users of this server and/or require the server to be rebooted for proper operation. In the case of a browser app using this library to act on invalid non-numeric data, that browser may crash or

CVE-2021-2419
Outside In Technology Web Database
7.5
HIGH
EPSS
1.0%
2021 1 PoC

Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the

CVE-2021-26419
Internet Explorer 11 General
7.5
HIGH
EPSS
34.1%
2021 1 PoC

Scripting Engine Memory Corruption Vulnerability

CVE-2021-32568
zmister2016/mrdoc General
7.5
HIGH
EPSS
0.3%
2021 CWE-502 1 PoC

mrdoc is vulnerable to Deserialization of Untrusted Data

CVE-2021-20124
🔥 KEV Draytek VigorConnect General ⚡ nuclei
7.5
HIGH
EPSS
94.1%
2021 1 PoC

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CVE-2021-30273
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables General
7.5
HIGH
EPSS
0.3%
2021 1 PoC

Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables

CVE-2021-23407
elFinder.Net.Core General
7.5
HIGH
EPSS
0.5%
2021 1 PoC

This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path.

CVE-2021-1980
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
7.5
HIGH
EPSS
0.4%
2021 1 PoC

Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2021-3805
mariocasciaro/object-path General
7.5
HIGH
EPSS
0.7%
2021 CWE-1321 1 PoC

object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')