Latest CVE Feed
-
2.5
LOWCVE-2021-25335
Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.... Read more
- EPSS Score: %0.05
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-25334
Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted application to cause permanent denial of service.... Read more
- EPSS Score: %0.02
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-25333
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.... Read more
Affected Products : pay_mini- EPSS Score: %0.07
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-25332
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.... Read more
Affected Products : pay_mini- EPSS Score: %0.07
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
3.2
LOWCVE-2021-25331
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.... Read more
Affected Products : pay_mini- EPSS Score: %0.07
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-25330
Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions including denial of service attack by hijacking the provider.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Mar. 02, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-25329
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable t... Read more
- EPSS Score: %4.62
- Published: Mar. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25328
Skyworth Digital Technology RN510 V.3.1.0.4 RN510 V.3.1.0.4 contains a buffer overflow vulnerability in /cgi-bin/app-staticIP.asp. An authenticated attacker can send a specially crafted request to endpoint which can lead to a denial of service (DoS) or po... Read more
- EPSS Score: %2.87
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-25327
Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-routeadd.asp and /cgi-bin/sec-urlfilter.asp. Missing CSRF protection in devices can lead to XSRF, as the above pages are vulnerable to c... Read more
- EPSS Score: %0.30
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-25326
Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_version.asp. If Wi-Fi is connected but an unauthenticated user visits a URL, the SSID password and web UI password may be disclosed.... Read more
- EPSS Score: %0.12
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25325
MISP 2.4.136 has XSS via galaxy cluster element values to app/View/GalaxyElements/ajax/index.ctp. Reference types could contain javascript: URLs.... Read more
- EPSS Score: %0.37
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-25324
MISP 2.4.136 has Stored XSS in the galaxy cluster view via a cluster name to app/View/GalaxyClusters/view.ctp.... Read more
- EPSS Score: %0.32
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-25323
The default setting of MISP 2.4.136 did not enable the requirements (aka require_password_confirmation) to provide the previous password when changing a password.... Read more
- EPSS Score: %0.26
- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25322
A UNIX Symbolic Link (Symlink) Following vulnerability in python-HyperKitty of openSUSE Leap 15.2, Factory allows local attackers to escalate privileges from the user hyperkitty or hyperkitty-admin to root. This issue affects: openSUSE Leap 15.2 python-Hy... Read more
- EPSS Score: %0.12
- Published: Jun. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25321
A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Factory, Leap 15.2 allows local attackers with control of the runtime user to... Read more
Affected Products : leap linux_enterprise_server manager_server arpwatch factory openldap2 openstack_cloud_crowbar- EPSS Score: %0.11
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
9.9
CRITICALCVE-2021-25320
A Improper Access Control vulnerability in Rancher, allows users in the cluster to make request to cloud providers by creating requests with the cloud-credential ID. Rancher in this case would attach the requested credentials without further checks This i... Read more
Affected Products : rancher- EPSS Score: %0.26
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25319
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.... Read more
- EPSS Score: %0.09
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25318
A Incorrect Permission Assignment for Critical Resource vulnerability in Rancher allows users in the cluster to modify resources they should not have access to. This issue affects: Rancher versions prior to 2.5.9 ; Rancher versions prior to 2.4.16.... Read more
Affected Products : rancher- EPSS Score: %0.12
- Published: Jul. 15, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-25317
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to... Read more
Affected Products : fedora leap linux_enterprise_server manager_server factory openldap2 cups openstack_cloud_crowbar- EPSS Score: %0.08
- Published: May. 05, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-25316
A Insecure Temporary File vulnerability in s390-tools of SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-SP2 allows local attackers to prevent VM live migrations This issue affects: SUSE Linux Enterprise Server 12-SP5 s390-tools versi... Read more
- EPSS Score: %0.04
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024