Latest CVE Feed
-
5.2
MEDIUMCVE-2021-25339
Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory.... Read more
- EPSS Score: %0.02
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
5.2
MEDIUMCVE-2021-25338
Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.... Read more
- EPSS Score: %0.02
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-25336
Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.... Read more
- EPSS Score: %0.05
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
2.5
LOWCVE-2021-25335
Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.... Read more
- EPSS Score: %0.05
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-25334
Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service.... Read more
- EPSS Score: %0.02
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-25333
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.... Read more
Affected Products : pay_mini- EPSS Score: %0.07
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-25332
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.... Read more
Affected Products : pay_mini- EPSS Score: %0.07
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-25331
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.... Read more
Affected Products : pay_mini- EPSS Score: %0.07
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25330
Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-25329
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable t... Read more
- EPSS Score: %4.62
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25328
Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially crafted request to endpoint which can lead to a denial of service (DoS) or po... Read more
- EPSS Score: %2.87
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-25327
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to c... Read more
- EPSS Score: %0.30
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25326
Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user visits a URL, the SSID password and web UI password may be disclosed.... Read more
- EPSS Score: %0.12
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25325
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.... Read more
- EPSS Score: %0.37
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25324
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.... Read more
- EPSS Score: %0.32
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25323
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.... Read more
- EPSS Score: %0.26
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25322
A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-Hy... Read more
- EPSS Score: %0.12
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25321
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to... Read more
Affected Products : leap linux_enterprise_server manager_server arpwatch factory openldap2 openstack_cloud_crowbar- EPSS Score: %0.11
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-25320
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This i... Read more
Affected Products : rancher- EPSS Score: %0.26
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25319
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.... Read more
- EPSS Score: %0.09
- Published: May. 05, 2021
- Modified: Nov. 21, 2024