7442 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25514
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2021 1 PoC

An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.

CVE-2021-25455
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2021 CWE-125 1 PoC

OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.

CVE-2021-25505
Samsung Pass General
3.3
LOW
EPSS
0.1%
2021 CWE-287 1 PoC

Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

CVE-2021-23896
McAfee Database Security (DBSec) General
3.2
LOW
EPSS
0.0%
2021 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security (DBSec) prior to 4.8.2 allows an administrator to view the unencrypted password of the McAfee Insights Server used to pass data to the Insights Server. This user is restricted to only have access to DBSec data in the Insights Server.

CVE-2021-25366
Samsung Internet General
3.2
LOW
EPSS
0.1%
2021 CWE-703 2 PoCs

Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.

CVE-2021-2123
VM VirtualBox Database
3.2
LOW
EPSS
0.0%
2021 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.18. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiali

CVE-2021-25333
Samsung Pay Mini General
3.2
LOW
EPSS
0.1%
2021 CWE-200 2 PoCs

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

CVE-2021-25351
Samsung Account General
3.2
LOW
EPSS
0.0%
2021 CWE-285 2 PoCs

Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

CVE-2021-25331
Samsung Pay Mini General
3.2
LOW
EPSS
0.1%
2021 CWE-200 2 PoCs

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.

CVE-2021-25332
Samsung Pay Mini General
3.2
LOW
EPSS
0.1%
2021 CWE-200 2 PoCs

Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.

CVE-2021-3944
bookstackapp/bookstack Web
3.1
LOW
EPSS
0.1%
2021 CWE-352 1 PoC

bookstack is vulnerable to Cross-Site Request Forgery (CSRF)

CVE-2021-21592
PowerScale OneFS General
3.1
LOW
EPSS
0.2%
2021 CWE-755 1 PoC

Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged user could potentially exploit this vulnerability, leading to unauthorized information disclosure.

CVE-2021-22151
Kibana General
3.1
LOW
EPSS
0.6%
2021 CWE-22 1 PoC

It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a malicious user could arbitrarily traverse the Kibana host to load internal files ending in the .pbf extension.

CVE-2021-23445
datatables.net General
3.1
LOW
EPSS
0.3%
2021 3 PoCs

This affects the package datatables.net before 1.11.3. If an array is passed to the HTML escape entities function it would not have its contents escaped.

CVE-2021-32618
flask-security General ⚡ nuclei
3.1
LOW
EPSS
17.1%
2021 CWE-601 0 PoCs

The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-Security-Too allow redirects after many successful views (e.g. /login) by honoring the ?next query param. There is code in FS to validate that the url specified in the next parameter is either relative OR has the same netloc (network location) as the requesting URL. This check utilizes Pythons urlsplit library. However many browsers are very lenient on the kin

CVE-2021-29776
QRadar SIEM General
3.1
LOW
EPSS
0.3%
2021 1 PoC

IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030.

CVE-2021-2341
Java SE JDK and JRE Database
3.1
LOW
EPSS
0.4%
2021 2 PoCs

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Jav

CVE-2021-35588
Java SE JDK and JRE Database
3.1
LOW
EPSS
0.2%
2021 1 PoC

Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 7u311, 8u301; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Oracle GraalVM Enterprise Edition. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (part

CVE-2021-2045
Text Database
3.1
LOW
EPSS
0.4%
2021 1 PoC

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Text. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).

CVE-2021-25376
Samsung Email General
3.1
LOW
EPSS
0.2%
2021 CWE-200 2 PoCs

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.