7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-21275
Report Web
5.3
MEDIUM
EPSS
0.2%
2021 CWE-352 2 PoCs

The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of MediaWiki edit tokens.

CVE-2021-47816
Thecus N4800Eco Nas Server Control Panel General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-78 1 PoC

Thecus N4800Eco NAS Server Control Panel contains a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands through user management endpoints. Attackers can inject commands via username and batch user creation parameters to execute shell commands with administrative privileges.

CVE-2021-20993
0852-0303 General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-200 1 PoC

In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.

CVE-2021-3820
pksunkara/inflect General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-1333 1 PoC

inflect is vulnerable to Inefficient Regular Expression Complexity

CVE-2021-27858
WARP Networking ⚡ nuclei
5.3
MEDIUM
EPSS
32.4%
2021 CWE-862 1 PoC

A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA004.

CVE-2021-21003
FL SWITCH General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-404 1 PoC

In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.

CVE-2021-35556
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerab

CVE-2021-34587
CC612 General
5.3
MEDIUM
EPSS
0.3%
2021 CWE-121 1 PoC

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

CVE-2021-22210
GitLab DevOps Web
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository branches through API, GitLab was ignoring a query parameter and returning a considerable amount of results.

CVE-2021-21702
PHP Web
5.3
MEDIUM
EPSS
0.3%
2021 CWE-476 1 PoC

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer and thus cause a crash.

CVE-2021-27656
exacqVision Web Service version 20.12.2.0 and prior General
5.3
MEDIUM
EPSS
0.2%
2021 1 PoC

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

CVE-2021-36327
Dell EMC Streaming Data Platform Web
5.3
MEDIUM
EPSS
0.3%
2021 CWE-918 1 PoC

Dell EMC Streaming Data Platform versions before 1.3 contain a Server Side Request Forgery Vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to perform port scanning of internal networks and make HTTP requests to an arbitrary domain of the attacker's choice.

CVE-2021-21344
xstream General
5.3
MEDIUM
EPSS
30.6%
2021 CWE-434 3 PoCs

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.

CVE-2021-35559
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerab

CVE-2021-36093
((OTRS)) Community Edition General
5.3
MEDIUM
EPSS
0.5%
2021 CWE-185 1 PoC

It's possible to create an email which can be stuck while being processed by PostMaster filters, causing DoS. This issue affects: OTRS AG ((OTRS)) Community Edition 6.0.x version 6.0.1 and later versions. OTRS AG OTRS 7.0.x version 7.0.28 and prior versions; 8.0.x version 8.0.15 and prior versions.

CVE-2021-3680
star7th/showdoc General
5.3
MEDIUM
EPSS
0.1%
2021 CWE-325 1 PoC

showdoc is vulnerable to Missing Cryptographic Step

CVE-2021-22017
🔥 KEV VMware vCenter Server, VMware Cloud Foundation Web Cloud ⚡ nuclei
5.3
MEDIUM
EPSS
74.8%
2021 1 PoC

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to bypass proxy leading to internal endpoints being accessed.

CVE-2021-23343
path-parse General
5.3
MEDIUM
EPSS
0.5%
2021 2 PoCs

All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, splitTailRe, and splitPathRe regular expressions. ReDoS exhibits polynomial worst-case time complexity.

CVE-2021-2457
Identity Manager Web Database
5.3
MEDIUM
EPSS
1.1%
2021 1 PoC

Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Request Management & Workflow). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-21707
PHP Web
5.3
MEDIUM
EPSS
0.6%
2021 CWE-159 1 PoC

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the function to interpret this as the end of the filename, thus interpreting the filename differently from what the user intended, which may lead it to reading a different file than intended.