7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25506
Samsung Health General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 1 PoC

Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

CVE-2021-21781
Linux Kernel General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-908 2 PoCs

An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11

CVE-2021-25390
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVE-2021-46679
Pandora FMS Web
4.0
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via service elements.

CVE-2021-25484
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-287 1 PoC

Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.

CVE-2021-25521
Samsung Internet General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-285 1 PoC

Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

CVE-2021-25341
S Assistant General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 2 PoCs

Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-46678
Pandora FMS Web
4.0
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the service name field.

CVE-2021-46681
Pandora FMS Web
4.0
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.

CVE-2021-25493
Samsung Notes General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read

CVE-2021-25460
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-285 1 PoC

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.

CVE-2021-3938
snipe/snipe-it Web
3.9
LOW
EPSS
0.2%
2021 CWE-79 1 PoC

snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2021-25475
Samsung Mobile Devices General
3.9
LOW
EPSS
0.0%
2021 CWE-122 1 PoC

A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

CVE-2021-45640
Software Genérico General
3.9
LOW
EPSS
0.6%
2021 1 PoC

Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.72, D6000 before 1.0.0.72, D6200 before 1.1.00.34, D6220 before 1.0.0.52, D6400 before 1.0.0.86, D7000 before 1.0.1.74, D7000v2 before 1.0.0.53, D7800 before 1.0.1.56, D8500 before 1.0.3.44, DC112A before 1.0.0.42, DGN2200v4 before 1.0.0.110, DGND2200Bv4 before 1.0.0.109, DM200 before 1.0.0.61, EX3700 before 1.0.0.76, EX3800 before 1.0.0.76, EX6120 before 1.0.0.46, EX6130 before 1.0.0.28, EX7000 before 1.0.1.78, PR2000 before 1.0.0.28, R6220 before 1.1.0.100, R6230 before 1.1.0

CVE-2021-2381
Solaris Operating System Database
3.9
LOW
EPSS
0.1%
2021 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle So

CVE-2021-45653
Software Genérico Cloud
3.9
LOW
EPSS
0.7%
2021 1 PoC

Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBK352 before 4.4.0.10, RBR350 before 4.4.0.10, and RBS350 before 4.4.0.10.

CVE-2021-34395
NVIDIA Jetson TX1 General
3.9
LOW
EPSS
0.0%
2021 1 PoC

Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.

CVE-2021-46762
2nd Gen AMD EPYC™ General
3.9
LOW
EPSS
0.0%
2021 2 PoCs

Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.

CVE-2021-32695
security-advisories Cloud
3.9
LOW
EPSS
0.6%
2021 CWE-200 1 PoC

Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same device could have gotten access to the shared preferences of the Nextcloud Android application. This required user-interaction as a victim had to initiate the sharing flow and choose the malicious app. The shared preferences contain some limited private data such as push tokens and the account name. The vulnerability is patched in version 3.16.1.

CVE-2021-2158
Hyperion Financial Management Web Database
3.9
LOW
EPSS
0.2%
2021 1 PoC

Vulnerability in the Hyperion Financial Management product of Oracle Hyperion (component: Task Automation). The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Financial Management. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Hyperion Financial Management accessible data as well as unauthorized read access to a subset of Hyperio