7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25736
Kubernetes DevOps Windows
5.8
MEDIUM
EPSS
0.1%
2021 1 PoC

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.

CVE-2021-29490
jellyfin Web ⚡ nuclei
5.8
MEDIUM
EPSS
88.2%
2021 CWE-918 0 PoCs

Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 vulnerable to unauthenticated Server-Side Request Forgery (SSRF) attacks via the imageUrl parameter. This issue potentially exposes both internal and external HTTP servers or other resources available via HTTP `GET` that are visible from the Jellyfin server. The vulnerability is patched in version 10.7.3. As a workaround, disable external access to the API endpoints `/Items/*/RemoteImages/Download`, `/Items/RemoteSearch/Image` and `/Images/Remote`

CVE-2021-2052
JD Edwards EnterpriseOne Orchestrator Web Database
5.8
MEDIUM
EPSS
0.6%
2021 1 PoC

Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). The supported version that is affected is Prior to 9.2.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Orchestrator. While the vulnerability is in JD Edwards EnterpriseOne Orchestrator, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of JD Edwards EnterpriseOne Orchestrator access

CVE-2021-40403
Gerbv General
5.8
MEDIUM
EPSS
0.2%
2021 CWE-456 1 PoC

An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2021-37861
Mattermost General
5.8
MEDIUM
EPSS
0.4%
2021 CWE-532 1 PoC

Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.

CVE-2021-4043
gpac/gpac General
5.8
MEDIUM
EPSS
1.5%
2021 CWE-476 1 PoC

NULL Pointer Dereference in GitHub repository gpac/gpac prior to 1.1.0.

CVE-2021-25507
Samsung Flow General
5.7
MEDIUM
EPSS
0.1%
2021 CWE-285 1 PoC

Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.

CVE-2021-36094
((OTRS)) Community Edition Web
5.7
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

It's possible to craft a request for appointment edit screen, which could lead to the XSS attack. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions.

CVE-2021-3426
python General
5.7
MEDIUM
EPSS
0.1%
2021 CWE-200 2 PoCs

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVE-2021-45523
Software Genérico General
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

NETGEAR R7000 devices before 1.0.9.42 are affected by a buffer overflow by an authenticated user.

CVE-2021-25501
Samsung Mobile Devices Cloud
5.7
MEDIUM
EPSS
0.0%
2021 CWE-284 1 PoC

An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

CVE-2021-21337
Products.PluggableAuthService General
5.7
MEDIUM
EPSS
1.8%
2021 CWE-601 1 PoC

Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthService before version 2.6.0 there is an open redirect vulnerability. A maliciously crafted link to the login form and login functionality could redirect the browser to a different website. The problem has been fixed in version 2.6.1. Depending on how you have installed Products.PluggableAuthService, you should change the buildout version pin to `2.6.1` and re-run the buildout, or if you used `pip` simply do `pip install "Products.PluggableAuthService>=2.6.1".

CVE-2021-35601
PeopleSoft Enterprise CS SA Integration Pack Database
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS SA Integration Pack product of Oracle PeopleSoft (component: Students Administration). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS SA Integration Pack executes to compromise PeopleSoft Enterprise CS SA Integration Pack. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS SA Inte

CVE-2021-25991
ifme General
5.7
MEDIUM
EPSS
0.2%
2021 CWE-284 1 PoC

In Ifme, versions v5.0.0 to v7.32 are vulnerable against an improper access control, which makes it possible for admins to ban themselves leading to their deactivation from Ifme account and complete loss of admin access to Ifme.

CVE-2021-41355
PowerShell 7.1 General
5.7
MEDIUM
EPSS
3.6%
2021 1 PoC

.NET Core and Visual Studio Information Disclosure Vulnerability

CVE-2021-35494
TIBCO JasperReports Server Web Cloud
5.7
MEDIUM
EPSS
0.2%
2021 1 PoC

The Rest API component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contain a race condition that allows a low privileged authenticated attacker via the REST API to obtain read access to temporary objects created by other users on the affected system. Affected rel

CVE-2021-35606
PeopleSoft Enterprise CS Campus Community Database
5.7
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Notification Framework). Supported versions that are affected are 9.0 and 9.2. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise CS Campus Community executes to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community

CVE-2021-2445
Hyperion Infrastructure Technology Web Database
5.7
MEDIUM
EPSS
1.3%
2021 1 PoC

Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.5.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as unau

CVE-2021-21435
OTRS General
5.7
MEDIUM
EPSS
0.3%
2021 CWE-200 1 PoC

Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface. This issue affects: OTRS AG OTRS 7.0.x version 7.0.23 and prior versions; 8.0.x version 8.0.10 and prior versions.

CVE-2021-30496
Software Genérico General
5.7
MEDIUM
EPSS
0.6%
2021 1 PoC

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKitFramework. NOTE: the vendor's perspective is that "this behavior can't be considered a vulnerability."