7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-31505
Q Plus Networking
6.8
MEDIUM
EPSS
0.3%
2021 CWE-798 1 PoC

This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus 1.9.0.3_278. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSH service. The device can be booted into a special operation mode where hard-coded credentials are accepted for SSH authentication. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-12890.

CVE-2021-46775
2nd Gen AMD EPYC™ General
6.8
MEDIUM
EPSS
0.1%
2021 1 PoC

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.

CVE-2021-21775
Webkit General
6.8
MEDIUM
EPSS
0.6%
2021 CWE-416 1 PoC

A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage.

CVE-2021-22214
GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
93.3%
2021 7 PoCs

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

CVE-2021-3645
viking04/merge General
6.8
MEDIUM
EPSS
0.5%
2021 CWE-1321 1 PoC

merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CVE-2021-38532
Software Genérico General
6.8
MEDIUM
EPSS
0.5%
2021 1 PoC

NETGEAR WAC104 devices before 1.0.4.15 are affected by incorrect configuration of security settings.

CVE-2021-32633
Zope General
6.8
MEDIUM
EPSS
0.9%
2021 CWE-22 1 PoC

Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules indirectly through Python modules that are available for direct use. By default, only users with the Manager role can add or edit Zope Page Templates through the web, but sites that allow untrusted users to add/edit Zope Page Templates through the web are at risk from this vulnerability. The problem has been fixed in Zope 5.2 and 4.6. As a workaround, a site administrator can restrict adding/editing Zope Page Templates through the web using the standard Zope user/role permis

CVE-2021-35567
Java SE JDK and JRE Database Windows
6.8
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Oracle GraalVM Enterprise Edition, attacks may significantly impact additional pr

CVE-2021-25397
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

CVE-2021-3879
snipe/snipe-it Web
6.8
MEDIUM
EPSS
0.5%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-21327
glpi General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-862 1 PoC

GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.4 non-authenticated user can remotely instantiate object of any class existing in the GLPI environment that can be used to carry out malicious attacks, or to start a “POP chain”. As an example of direct impact, this vulnerability affects integrity of the GLPI core platform and third-party plugins runtime misusing classes which implement some sensitive operations in their constructors or destructors. This is fixed in versio

CVE-2021-47759
MTPutty Networking Windows
6.8
MEDIUM
EPSS
0.0%
2021 CWE-522 1 PoC

MTPutty 1.0.1.21 contains a sensitive information disclosure vulnerability that allows local attackers to view SSH connection passwords through Windows PowerShell process listing. Attackers can run a PowerShell command to retrieve the full command line of MTPutty processes, exposing plaintext SSH credentials.

CVE-2021-3866
zulip/zulip Web
6.8
MEDIUM
EPSS
0.6%
2021 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6af710438b153d and prior to 3eb2791c3e9695f7d37ffe84e0c2184fae665cb6.

CVE-2021-25363
Samsung Mobile Devices General
6.8
MEDIUM
EPSS
0.0%
2021 CWE-269 2 PoCs

An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.

CVE-2021-38522
Software Genérico General
6.8
MEDIUM
EPSS
0.5%
2021 1 PoC

NETGEAR R6400 devices before 1.0.1.52 are affected by a stack-based buffer overflow by an authenticated user.

CVE-2021-22175
🔥 KEV GitLab DevOps ⚡ nuclei
6.8
MEDIUM
EPSS
69.7%
2021 1 PoC

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

CVE-2021-4187
vim/vim General
6.8
MEDIUM
EPSS
0.3%
2021 CWE-416 1 PoC

vim is vulnerable to Use After Free

CVE-2021-21353
pug General
6.8
MEDIUM
EPSS
1.9%
2021 CWE-74 1 PoC

Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object such as the query parameters of a request into the pug template inputs, it was possible for them to achieve remote code execution on the node.js backend. This is fixed in version 3.0.1. This advisory applies to multiple pug packages including "pug", "pug-code-gen". pug-code-gen has a backported fix at version 2.0.3. This advisory is not exploitable if there is no way for un-

CVE-2021-47771
RDP Manager Windows
6.8
MEDIUM
EPSS
0.0%
2021 CWE-770 2 PoCs

RDP Manager 4.9.9.3 contains a denial of service vulnerability in connection input fields that allows local attackers to crash the application. Attackers can add oversized entries in Verbindungsname and Server fields to permanently freeze and crash the software, potentially requiring full reinstallation.