Latest CVE Feed
-
9.8
CRITICALCVE-2021-26689
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. The USB laf gadget has a use-after-free. The LG ID is LVE-SMP-200031 (February 2021).... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26688
An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security properties. The LG ID is LVE-SMP-200030 (February 2021).... Read more
- EPSS Score: %0.15
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26687
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, the HostnameVerified default is mishandled. The LG ID is LVE-SMP-200029 (February 2021).... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26686
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated rem... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.20
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26685
A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface API of ClearPass could allow an authenticated rem... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.20
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26684
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %3.29
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26683
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %3.29
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26682
A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the guest portal interface of ClearPass could allow a remote attacker to con... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.25
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26681
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authenticated users to run arbitrary command... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %3.56
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26680
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %1.84
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26679
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %3.29
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-26678
A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the web-based management interface of ClearPass could allow an ... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %0.47
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26677
A local authenticated escalation of privilege vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in ClearPass OnGuard could allow local authenticated users on a Windows platfor... Read more
- EPSS Score: %0.04
- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-26676
gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.... Read more
- EPSS Score: %0.11
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-26675
A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.... Read more
- EPSS Score: %0.22
- Published: Feb. 09, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26644
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is ... Read more
- EPSS Score: %1.15
- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26642
When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file can be uploaded due to insufficient verification of the file. A remote attacker can use this vulnerability to execute arbitrary code o... Read more
- EPSS Score: %2.89
- Published: Jan. 20, 2023
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-26639
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Remote attackers can use this vulnerability to leak all files in the server without logging in system.... Read more
- EPSS Score: %0.12
- Published: Aug. 17, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-26638
Improper Authentication vulnerability in S&D smarthome(smartcare) application can cause authentication bypass and information exposure. Remote attackers can use this vulerability to take control of the home environment including indoor control.... Read more
Affected Products : s\&d_smarthome- EPSS Score: %8.75
- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-26637
There is no account authentication and permission check logic in the firmware and existing apps of SiHAS's SGW-300, ACM-300, GCM-300, so unauthorized users can remotely control the device.... Read more
- EPSS Score: %0.93
- Published: Jun. 23, 2022
- Modified: Nov. 21, 2024