7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-3904
getgrav/grav Web
6.3
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

grav is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-3758
bookstackapp/bookstack General
6.3
MEDIUM
EPSS
0.2%
2021 CWE-918 1 PoC

bookstack is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2021-3983
kevinpapst/kimai2 Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-79 1 PoC

kimai2 is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-23348
portprocesses General
6.3
MEDIUM
EPSS
1.1%
2021 1 PoC

This affects the package portprocesses before 1.0.5. If (attacker-controlled) user input is given to the killProcess function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

CVE-2021-4264
dustjs General
6.3
MEDIUM
EPSS
0.7%
2021 CWE-1321 1 PoC

A vulnerability was found in LinkedIn dustjs up to 2.x and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.0 is able to address this issue. The name of the patch is ddb6523832465d38c9d80189e9de60519ac307c3. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216464.

CVE-2021-4097
phpservermon/phpservermon Web
6.3
MEDIUM
EPSS
0.2%
2021 CWE-93 1 PoC

phpservermon is vulnerable to Improper Neutralization of CRLF Sequences

CVE-2021-38539
Software Genérico General
6.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Certain NETGEAR devices are affected by privilege escalation. This affects D8500 before 1.0.3.44, R6400v2 before 1.0.2.66, R6700 before 1.0.2.6, R6700v3 before 1.0.2.66, R6900 before 1.0.2.4, R6900P before 1.3.2.126, R7000 before 1.0.9.42, R7000P before 1.3.2.126, R7100LG before 1.0.0.50, R7300DST before 1.0.0.70, R7900 before 1.0.3.10, R8300 before 1.0.2.130, and R8500 before 1.0.2.130.

CVE-2021-35500
TIBCO Data Virtualization Cloud
6.3
MEDIUM
EPSS
0.1%
2021 1 PoC

The Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, TIBCO Data Virtualization, and TIBCO Data Virtualization for AWS Marketplace contains a difficult to exploit vulnerability that allows a low privileged attacker with local access to download arbitrary files outside of the scope of the user's permissions on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Data Virtualization: versions 8.3.0 and below, TIBCO Data Virtualization: version 8.4.0, TIBCO Data Virtualization: version 8.5.0, and TIBCO Data Virtua

CVE-2021-22191
Wireshark General
6.3
MEDIUM
EPSS
0.3%
2021 3 PoCs

Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet injection or crafted capture file.

CVE-2021-23400
nodemailer Web
6.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

The package nodemailer before 6.6.1 are vulnerable to HTTP Header Injection if unsanitized user input that may contain newlines and carriage returns is passed into an address object.

CVE-2021-27254
R7800 General
6.3
MEDIUM
EPSS
0.1%
2021 CWE-259 1 PoC

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800. Authentication is not required to exploit this vulnerability. The specific flaw exists within the apply_save.cgi endpoint. This issue results from the use of hard-coded encryption key. An attacker can leverage this vulnerability to execute arbitrary code in the context of root. Was ZDI-CAN-12287.

CVE-2021-2057
Retail Customer Management and Segmentation Foundation Web Database
6.3
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Internal Operations). The supported version that is affected is 19.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Retail Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to

CVE-2021-25511
Samsung Mobile Devices General
6.3
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

CVE-2021-35594
MySQL Cluster Database
6.3
MEDIUM
EPSS
39.3%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3

CVE-2021-24006
Fortinet FortiManager Networking
6.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile to access the SD-WAN Orchestrator panel via directly visiting its URL.

CVE-2021-35598
MySQL Cluster Database
6.3
MEDIUM
EPSS
39.3%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3

CVE-2021-34387
NVIDIA Jetson TX1 General
6.3
MEDIUM
EPSS
0.0%
2021 1 PoC

The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.

CVE-2021-23327
apexcharts Web
6.3
MEDIUM
EPSS
0.3%
2021 2 PoCs

The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph legend fields.

CVE-2021-35590
MySQL Cluster Database
6.3
MEDIUM
EPSS
46.9%
2021 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.4.33 and prior, 7.5.23 and prior, 7.6.19 and prior and 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 6.3

CVE-2021-4328
狮子鱼CMS Web Database
6.3
MEDIUM
EPSS
0.4%
2021 CWE-89 1 PoC

A vulnerability has been found in 狮子鱼CMS and classified as critical. Affected by this vulnerability is the function goods_detail of the file ApiController.class.php. The manipulation of the argument goods_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The associated identifier of this vulnerability is VDB-222223.