3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-23883
Endpoint Security (ENS) for Windows Windows
4.0
MEDIUM
EPSS
0.1%
2021 CWE-476 1 PoC

A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. This varies by machine and had partial protection prior to this update.

CVE-2021-25359
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-284 2 PoCs

An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.

CVE-2021-46676
Pandora FMS Web
4.0
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the transactional maps name field.

CVE-2021-2152
Business Intelligence Enterprise Edition Web Database
4.0
MEDIUM
EPSS
0.2%
2021 1 PoC

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional

CVE-2021-25515
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-269 1 PoC

An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

CVE-2021-25364
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-200 2 PoCs

A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.

CVE-2021-25526
Samsung Blockchain Wallet General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-926 1 PoC

Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.

CVE-2021-25459
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-285 1 PoC

An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.

CVE-2021-23566
nanoid General
4.0
MEDIUM
EPSS
0.0%
2021 2 PoCs

The package nanoid from 3.0.0 and before 3.1.31 are vulnerable to Information Exposure via the valueOf() function which allows to reproduce the last id generated.

CVE-2021-25484
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-287 1 PoC

Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.

CVE-2021-46679
Pandora FMS Web
4.0
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.