Latest CVE Feed
-
4.8
MEDIUMCVE-2021-25273
Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.... Read more
Affected Products : unified_threat_management- EPSS Score: %0.14
- Published: Jul. 29, 2021
- Modified: Nov. 21, 2024
-
6.0
MEDIUMCVE-2021-25271
A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.... Read more
Affected Products : hitmanpro- EPSS Score: %0.05
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25270
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.... Read more
Affected Products : hitmanpro.alert- EPSS Score: %0.05
- Published: Oct. 08, 2021
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2021-25269
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23... Read more
- EPSS Score: %0.05
- Published: Nov. 26, 2021
- Modified: Nov. 21, 2024
-
8.4
HIGHCVE-2021-25268
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.... Read more
- EPSS Score: %0.16
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-25267
Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.... Read more
- EPSS Score: %0.21
- Published: May. 05, 2022
- Modified: Nov. 21, 2024
-
3.9
LOWCVE-2021-25266
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.349... Read more
- EPSS Score: %0.05
- Published: Apr. 27, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-25265
A malicious website could execute code remotely in Sophos Connect Client before version 2.1.... Read more
- EPSS Score: %0.25
- Published: Mar. 22, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25264
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.... Read more
- EPSS Score: %0.02
- Published: May. 17, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25263
Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Br... Read more
Affected Products : yandex_browser- EPSS Score: %0.09
- Published: Aug. 17, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25261
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update pr... Read more
- EPSS Score: %0.03
- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25253
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an atta... Read more
- EPSS Score: %1.09
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-25252
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.... Read more
Affected Products : linux_kernel macos netware interscan_web_security_virtual_appliance windows deep_discovery_inspector apex_one worry-free_business_security control_manager officescan +15 more products- EPSS Score: %0.06
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-25251
The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administ... Read more
- EPSS Score: %0.86
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25250
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must firs... Read more
- EPSS Score: %0.07
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25249
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installatio... Read more
- EPSS Score: %0.08
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-25248
An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe... Read more
- EPSS Score: %0.15
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-25247
A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on t... Read more
- EPSS Score: %0.09
- Published: Jan. 27, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-25246
An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that coul... Read more
- EPSS Score: %0.36
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-25245
An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.... Read more
Affected Products : worry-free_business_security- EPSS Score: %0.38
- Published: Feb. 04, 2021
- Modified: Nov. 21, 2024