Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2021-25273

    Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.... Read more

    Affected Products : unified_threat_management
    • EPSS Score: %0.14
    • Published: Jul. 29, 2021
    • Modified: Nov. 21, 2024
  • 6.0

    MEDIUM
    CVE-2021-25271

    A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.... Read more

    Affected Products : hitmanpro
    • EPSS Score: %0.05
    • Published: Oct. 08, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-25270

    A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.... Read more

    Affected Products : hitmanpro.alert
    • EPSS Score: %0.05
    • Published: Oct. 08, 2021
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2021-25269

    A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23... Read more

    • EPSS Score: %0.05
    • Published: Nov. 26, 2021
    • Modified: Nov. 21, 2024
  • 8.4

    HIGH
    CVE-2021-25268

    Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.... Read more

    Affected Products : firewall firewall_firmware firewall
    • EPSS Score: %0.16
    • Published: May. 05, 2022
    • Modified: Nov. 21, 2024
  • 8.5

    HIGH
    CVE-2021-25267

    Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA.... Read more

    Affected Products : firewall firewall_firmware firewall
    • EPSS Score: %0.21
    • Published: May. 05, 2022
    • Modified: Nov. 21, 2024
  • 3.9

    LOW
    CVE-2021-25266

    An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.349... Read more

    Affected Products : intercept_x authenticator
    • EPSS Score: %0.05
    • Published: Apr. 27, 2022
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2021-25265

    A malicious website could execute code remotely in Sophos Connect Client before version 2.1.... Read more

    Affected Products : windows connect
    • EPSS Score: %0.25
    • Published: Mar. 22, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-25264

    In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.... Read more

    Affected Products : home intercept_x
    • EPSS Score: %0.02
    • Published: May. 17, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-25263

    Local privilege vulnerability in Yandex Browser for Windows prior to 21.9.0.390 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating files in directory with insecure permissions during Yandex Br... Read more

    Affected Products : yandex_browser
    • EPSS Score: %0.09
    • Published: Aug. 17, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-25261

    Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update pr... Read more

    Affected Products : windows yandex_browser
    • EPSS Score: %0.03
    • Published: Jun. 15, 2022
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-25253

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an atta... Read more

    Affected Products : apex_one officescan
    • EPSS Score: %1.09
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-25252

    Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.... Read more

    • EPSS Score: %0.06
    • Published: Mar. 03, 2021
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2021-25251

    The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administ... Read more

    • EPSS Score: %0.86
    • Published: Feb. 10, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-25250

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must firs... Read more

    Affected Products : apex_one officescan
    • EPSS Score: %0.07
    • Published: Apr. 13, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-25249

    An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installatio... Read more

    • EPSS Score: %0.08
    • Published: Feb. 04, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2021-25248

    An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe... Read more

    • EPSS Score: %0.15
    • Published: Feb. 04, 2021
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2021-25247

    A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on t... Read more

    Affected Products : windows housecall_for_home_networks
    • EPSS Score: %0.09
    • Published: Jan. 27, 2021
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2021-25246

    An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that coul... Read more

    • EPSS Score: %0.36
    • Published: Feb. 04, 2021
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2021-25245

    An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.... Read more

    Affected Products : worry-free_business_security
    • EPSS Score: %0.38
    • Published: Feb. 04, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291305 Results