7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-4121
yetiforcecompany/yetiforcecrm Web
6.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-25518
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.0%
2021 CWE-119 1 PoC

An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-36293
VNX2 General
6.4
MEDIUM
EPSS
0.1%
2021 CWE-78 1 PoC

Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially exploit vulnerability and gain elevated privileges.

CVE-2021-4108
snipe/snipe-it Web
6.4
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-32644
ampache Web
6.4
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

Ampache is an open source web based audio/video streaming application and file manager. Due to a lack of input filtering versions 4.x.y are vulnerable to code injection in random.php. The attack requires user authentication to access the random.php page unless the site is running in demo mode. This issue has been resolved in 4.4.3.

CVE-2021-23556
guake General
6.4
MEDIUM
EPSS
0.8%
2021 1 PoC

The package guake before 3.8.5 are vulnerable to Exposed Dangerous Method or Function due to the exposure of execute_command and execute_command_by_uuid methods via the d-bus interface, which makes it possible for a malicious user to run an arbitrary command via the d-bus method. **Note:** Exploitation requires the user to have installed another malicious program that will be able to send dbus signals or run terminal commands.

CVE-2021-36100
OTRS General
6.4
MEDIUM
EPSS
0.7%
2021 1 PoC

Specially crafted string in OTRS system configuration can allow the execution of any system command.

CVE-2021-25516
Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.1%
2021 CWE-703 1 PoC

An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

CVE-2021-3485
Endpoint Security Tools for Linux General
6.4
MEDIUM
EPSS
0.8%
2021 CWE-494 1 PoC

An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linux allows a man-in-the-middle attacker to abuse the DownloadFile function of the Product Update to achieve remote code execution. This issue affects: Bitdefender Endpoint Security Tools for Linux versions prior to 6.2.21.155.

CVE-2021-25394
🔥 KEV Samsung Mobile Devices General
6.4
MEDIUM
EPSS
0.4%
2021 CWE-416 1 PoC

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

CVE-2021-38539
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.10, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

CVE-2021-35592
MySQL Cluster Database
6.3
MEDIUM
EPSS
28.6%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3 (Confidentiality,

CVE-2021-3904
getgrav/grav Web
6.3
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-34384
NVIDIA Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX General
6.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.

CVE-2021-38519
Software Genérico General
6.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6700 before 1.0.2.8, R6900 before 1.0.2.8, R7000 before 1.0.9.88, R6900P before 1.3.2.132, R7100LG before 1.0.0.52, R7900 before 1.0.3.10, R8000 before 1.0.4.46, R7900P before 1.4.1.50, R8000P before 1.4.1.50, and RAX80 before 1.0.1.40.

CVE-2021-25511
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

CVE-2021-34388
NVIDIA Jetson TX1, TX2 series, TX2 NX, AGX Xavier series, Xavier NX, Nano and Nano 2GB General
6.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

CVE-2021-38615
Software Genérico General
6.3
MEDIUM
EPSS
0.3%
2021 1 PoC

In Eigen NLP 3.10.1, a lack of access control on the /auth/v1/sso/config/ SSO configuration endpoint allows any logged-in user (guest, standard, or admin) to view and modify information.

CVE-2021-29449
pi-hole General
6.3
MEDIUM
EPSS
11.4%
2021 CWE-269 1 PoC

Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. Multiple privilege escalation vulnerabilities were discovered in version 5.2.4 of Pi-hole core. See the referenced GitHub security advisory for details.

CVE-2021-3818
getgrav/grav General
6.3
MEDIUM
EPSS
0.3%
2021 CWE-565 1 PoC

grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking