7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-22876
https://github.com/curl/curl Web
5.3
MEDIUM
EPSS
0.1%
2021 CWE-359 1 PoC

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leaking sensitive data to the server that is the target of the second HTTP request.

CVE-2021-35564
Java SE JDK and JRE Database
5.3
MEDIUM
EPSS
0.1%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerabi

CVE-2021-2407
PeopleSoft Enterprise PT PeopleTools Web Database
5.3
MEDIUM
EPSS
0.8%
2021 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.57, 8.58 and 8.59. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-30169
P2/Z2/P3/Z3 IP camera firmware General
5.3
MEDIUM
EPSS
1.0%
2021 CWE-200 1 PoC

The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.

CVE-2021-22248
GitLab DevOps
5.3
MEDIUM
EPSS
0.2%
2021 1 PoC

Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline information for public projects that have access to pipelines restricted to members only

CVE-2021-36199
VideoEdge General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-228 1 PoC

Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.

CVE-2021-25510
Samsung Mobile Devices General
5.3
MEDIUM
EPSS
0.0%
2021 CWE-20 1 PoC

An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

CVE-2021-26085
🔥 KEV Confluence Server General ⚡ nuclei
5.3
MEDIUM
EPSS
94.0%
2021 3 PoCs

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versions are before version 7.4.10, and from version 7.5.0 before 7.12.3.

CVE-2021-35655
Hyperion Essbase Administration Services Web Database
5.3
MEDIUM
EPSS
0.8%
2021 1 PoC

Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported versions that are affected are Prior to 11.1.2.4.046 and Prior to 21.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Essbase Administration Services. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Essbase Administration Services accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2021-32785
mod_auth_openidc Web Database
5.3
MEDIUM
EPSS
1.6%
2021 CWE-134 1 PoC

mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. When mod_auth_openidc versions prior to 2.4.9 are configured to use an unencrypted Redis cache (`OIDCCacheEncrypt off`, `OIDCSessionType server-cache`, `OIDCCacheType redis`), `mod_auth_openidc` wrongly performed argument interpolation before passing Redis requests to `hiredis`, which would perform it again and lead to an uncontrolled format string bug. Initial assessment shows that this bug does no

CVE-2021-25219
BIND9 General
5.3
MEDIUM
EPSS
1.0%
2021 1 PoC

In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.

CVE-2021-38314
Gutenberg Template Library & Redux Framework Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
84.1%
2021 CWE-200 8 PoCs

The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress registered several AJAX actions available to unauthenticated users in the `includes` function in `redux-core/class-redux-core.php` that were unique to a given site but deterministic and predictable given that they were based on an md5 hash of the site URL with a known salt value of '-redux' and an md5 hash of the previous hash with a known salt value of '-support'. These AJAX actions could be used to retrieve a list of active plugins and their versions, the site's PHP version, and an unsalted md5 hash of site’s `AU

CVE-2021-39327
BulletProof Security Web Windows ⚡ nuclei
5.3
MEDIUM
EPSS
90.9%
2021 CWE-200 2 PoCs

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

CVE-2021-20996
0852-0303 General
5.3
MEDIUM
EPSS
0.2%
2021 CWE-732 1 PoC

In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.

CVE-2021-42794
Software Genérico General
5.3
MEDIUM
EPSS
0.3%
2021 1 PoC

An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.

CVE-2021-1472
Cisco Small Business RV Series Router Firmware Networking ⚡ nuclei
5.3
MEDIUM
EPSS
91.3%
2021 CWE-119 1 PoC

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2021-2006
MySQL Server Web Database
5.3
MEDIUM
EPSS
1.1%
2021 1 PoC

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).

CVE-2021-21973
🔥 KEV VMware vCenter Server Cloud ⚡ nuclei
5.3
MEDIUM
EPSS
90.4%
2021 1 PoC

The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of URLs in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue by sending a POST request to vCenter Server plugin leading to information disclosure. This affects: VMware vCenter Server (7.x before 7.0 U1c, 6.7 before 6.7 U3l and 6.5 before 6.5 U3n) and VMware Cloud Foundation (4.x before 4.2 and 3.x before 3.10.1.2).

CVE-2021-47783
Phpwcms Web
5.3
MEDIUM
EPSS
0.0%
2021 CWE-434 1 PoC

Phpwcms 1.9.30 contains a file upload vulnerability that allows authenticated attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG payloads through the multiple file upload feature to potentially execute cross-site scripting attacks on the platform.

CVE-2021-23368
postcss General
5.3
MEDIUM
EPSS
0.3%
2021 2 PoCs

The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during source map parsing.