7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-23444
jointjs General
5.6
MEDIUM
EPSS
1.5%
2021 3 PoCs

This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 when the user-provided keys used in the path parameter are arrays in the setByPath function.

CVE-2021-23421
merge-change General
5.6
MEDIUM
EPSS
0.5%
2021 1 PoC

All versions of package merge-change are vulnerable to Prototype Pollution via the utils.set function.

CVE-2021-45664
Software Genérico Web
5.6
MEDIUM
EPSS
0.3%
2021 1 PoC

NETGEAR R7000 devices before 1.0.11.126 are affected by stored XSS.

CVE-2021-31955
🔥 KEV Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
4.1%
2021 1 PoC

Windows Kernel Information Disclosure Vulnerability

CVE-2021-1112
Jetson AGX Xavier series, Jetson Xavier NX, Jetson TX2 series, Jetson TX2 NX, Jetson Nano, Jetson Nano 2GB, Jetson TX1 General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where a null pointer dereference may lead to complete denial of service.

CVE-2021-31184
Windows 10 Version 1803 Windows
5.5
MEDIUM
EPSS
2.4%
2021 1 PoC

Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability

CVE-2021-1258
Cisco AnyConnect Secure Mobility Client Networking
5.5
MEDIUM
EPSS
0.0%
2021 CWE-264 2 PoCs

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker could exploit this vulnerability by sending a crafted command from the local CLI to the application. A successful exploit could allow the attacker to read arbitrary files on the underlying OS of the affected device. The attacker would need to have valid user credentials to exploit

CVE-2021-33910
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVE-2021-26355
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

CVE-2021-1930
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2021-42375
busybox General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-159 2 PoCs

An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.

CVE-2021-33602
F-Secure endpoint protection products on Windows and Mac. F-Secure Linux Security (32-bit) F-Secure Linux Security 64 F-Secure Atlant & F-Secure Cloud Protection for Salesforce Cloud Windows
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

A vulnerability affecting the F-Secure Antivirus engine was discovered when the engine tries to unpack a zip archive (LZW decompression method), and this can crash the scanning engine. The vulnerability can be exploited remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine.

CVE-2021-28507
EOS General
5.5
MEDIUM
EPSS
0.1%
2021 CWE-284 1 PoC

An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.

CVE-2021-38926
DB2 for Linux, UNIX and Windows Windows
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local user to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 210321.

CVE-2021-1123
NVIDIA Virtual GPU Software General
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can deadlock, which may lead to denial of service.

CVE-2021-35604
MySQL Server Database
5.5
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability im

CVE-2021-4298
Sipity Database
5.5
MEDIUM
EPSS
0.3%
2021 CWE-89 1 PoC

A vulnerability classified as critical has been found in Hesburgh Libraries of Notre Dame Sipity. This affects the function SearchCriteriaForWorksParameter of the file app/parameters/sipity/parameters/search_criteria_for_works_parameter.rb. The manipulation leads to sql injection. Upgrading to version 2021.8 is able to address this issue. The patch is named d1704c7363b899ffce65be03a796a0ee5fdbfbdc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217179.

CVE-2021-1101
NVIDIA Virtual GPU Software General
5.5
MEDIUM
EPSS
0.0%
2021 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-43224
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
12.7%
2021 1 PoC

Windows Common Log File System Driver Information Disclosure Vulnerability