7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-46768
2nd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.

CVE-2021-37850
ESET Cyber Security General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to the system to stop the ESET daemon, effectively disabling the protection of the ESET security product until a system reboot.

CVE-2021-4245
rfc6902 General
5.5
MEDIUM
EPSS
0.7%
2021 CWE-74 1 PoC

A vulnerability classified as problematic has been found in chbrown rfc6902. This affects an unknown part of the file pointer.ts. The manipulation leads to improperly controlled modification of object prototype attributes ('prototype pollution'). The exploit has been disclosed to the public and may be used. The name of the patch is c006ce9faa43d31edb34924f1df7b79c137096cf. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-215883.

CVE-2021-4315
psiTurk General
5.5
MEDIUM
EPSS
0.6%
2021 CWE-1336 1 PoC

A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/experiment.py. The manipulation of the argument mode leads to improper neutralization of special elements used in a template engine. The exploit has been disclosed to the public and may be used. Upgrading to version 3.2.1 is able to address this issue. The name of the patch is 47787e15cecd66f2aa87687bf852ae0194a4335f. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-219676.

CVE-2021-21411
oauth2-proxy DevOps
5.5
MEDIUM
EPSS
0.2%
2021 CWE-863 1 PoC

OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `--gitlab-group` flag for group-based authorization in the GitLab provider stopped working in the v7.0.0 release. Regardless of the flag settings, authorization wasn't restricted. Additionally, any authenticated users had whichever groups were set in `--gitlab-group` added to the new `X-Forwarded-Groups` header to the upstream application. While adding GitLab project based authorization support in #630, a bug was introduced where the user session's groups field was populated wi

CVE-2021-26343
3rd Gen EPYC General
5.5
MEDIUM
EPSS
0.1%
2021 1 PoC

Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.

CVE-2021-43224
Windows 10 Version 1809 Windows
5.5
MEDIUM
EPSS
12.7%
2021 1 PoC

Windows Common Log File System Driver Information Disclosure Vulnerability

CVE-2021-33910
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2021 2 PoCs

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

CVE-2021-34560
WHA-GW-F2D2-0-AS- Z2-ETH Networking
5.5
MEDIUM
EPSS
0.1%
2021 CWE-522 1 PoC

In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored credentials can be captured by an attacker who gains control over the user's computer. Therefore the user must have logged in at least once.

CVE-2021-35551
Database - Enterprise Edition Database
5.5
MEDIUM
EPSS
0.3%
2021 1 PoC

Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS Security as well as unauthorized update, insert or delete access to some of RDBMS Security accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impac

CVE-2021-35612
MySQL Server Database
5.5
MEDIUM
EPSS
0.4%
2021 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CV

CVE-2021-4183
Wireshark General
5.5
MEDIUM
EPSS
0.2%
2021 1 PoC

Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file

CVE-2021-25355
Samsung Notes General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-285 2 PoCs

Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

CVE-2021-1656
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
1.7%
2021 1 PoC

TPM Device Driver Information Disclosure Vulnerability

CVE-2021-1699
Windows 10 Version 20H2 Windows
5.5
MEDIUM
EPSS
0.8%
2021 1 PoC

Windows (modem.sys) Information Disclosure Vulnerability

CVE-2021-24098
Windows 10 Version 2004 Windows
5.5
MEDIUM
EPSS
2.0%
2021 1 PoC

Windows Console Driver Denial of Service Vulnerability

CVE-2021-36873
iQ Block Country Web Windows ⚡ nuclei
5.5
MEDIUM
EPSS
1.8%
2021 CWE-79 0 PoCs

Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress iQ Block Country plugin (versions <= 1.2.11). Vulnerable parameter: &blockcountry_blockmessage.

CVE-2021-25334
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.0%
2021 CWE-20 2 PoCs

Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service.

CVE-2021-30657
🔥 KEV macOS General
5.5
MEDIUM
EPSS
83.1%
2021 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..

CVE-2021-45067
Acrobat Reader General
5.5
MEDIUM
EPSS
1.8%
2021 CWE-788 1 PoC

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.