CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2022-22290

    Last Modified: 21 Nov 2024

    Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.

    Published: 14 Jan 2022
    9.1
    Critical

    CVE-2021-28500

    Last Modified: 21 Nov 2024

    An issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.

    Published: 14 Jan 2022
    8.1
    High

    CVE-2022-0130

    Last Modified: 21 Nov 2024

    Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a specific file type in the web server root of the Tenable.sc host prior to remote exploitation.

    Published: 14 Jan 2022
    6.1
    Medium

    CVE-2021-38127

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).

    Published: 14 Jan 2022
    6.1
    Medium

    CVE-2021-38126

    Last Modified: 21 Nov 2024

    Potential vulnerabilities have been identified in Micro Focus ArcSight Enterprise Security Manager, affecting versions 7.4.x and 7.5.x. The vulnerabilities could be remotely exploited resulting in Cross-Site Scripting (XSS).

    Published: 14 Jan 2022
    4.3
    Medium

    CVE-2021-42067

    Last Modified: 21 Nov 2024

    In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which they would not normally be allowed to see. No information alteration or denial of service is possible.

    Published: 14 Jan 2022
    6.1
    Medium

    CVE-2022-22529

    Last Modified: 24 Feb 2026

    SAP Enterprise Threat Detection (ETD) - version 2.0, does not sufficiently encode user-controlled inputs which may lead to an unauthorized attacker possibly exploit XSS vulnerability. The UIs in ETD are using SAP UI5 standard controls, the UI5 framework provides automated output encoding for its standard controls. This output encoding prevents stored malicious user input from being executed when it is reflected in the UI.

    Published: 14 Jan 2022
    8.1
    High

    CVE-2022-22531

    Last Modified: 24 Feb 2026

    The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to run arbitrary script code, resulting in sensitive information being disclosed or modified.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-44234

    Last Modified: 21 Nov 2024

    SAP Business One - version 10.0, extended log stores information that can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

    Published: 14 Jan 2022
    8.1
    High

    CVE-2022-22530

    Last Modified: 24 Feb 2026

    The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical information being modified or completely compromise the availability of the application.

    Published: 14 Jan 2022
    5.3
    Medium

    CVE-2021-1037

    Last Modified: 21 Nov 2024

    The broadcast that DevicePickerFragment sends when a new device is paired doesn't have any permission checks, so any app can register to listen for it. This lets apps keep track of what devices are paired without requesting BLUETOOTH permissions.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-162951906

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-1036

    Last Modified: 21 Nov 2024

    In LocationSettingsActivity of AndroidManifest.xml, there is a possible EoP due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-182812255

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-1035

    Last Modified: 21 Nov 2024

    In setLaunchIntent of BluetoothDevicePickerPreferenceController.java, there is a possible way to invoke an arbitrary broadcast receiver due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-12Android ID: A-195668284

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39684

    Last Modified: 21 Nov 2024

    In target_init of gs101/abl/target/slider/target.c, there is a possible allocation of RWX memory due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-203250788References: N/A

    Published: 14 Jan 2022
    6.7
    Medium

    CVE-2021-39683

    Last Modified: 21 Nov 2024

    In copy_from_mbox of sss_ice_util.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-202003354References: N/A

    Published: 14 Jan 2022
    7.5
    High

    CVE-2021-45773

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in CS104_IPAddress_setFromString at src/iec60870/cs104/cs104_slave.c of lib60870 commit 0d5e76e can lead to a segmentation fault or application crash.

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39682

    Last Modified: 21 Nov 2024

    In mgm_alloc_page of memory_group_manager.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-201677538References: N/A

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39681

    Last Modified: 21 Nov 2024

    In delete_protocol of main.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-200251074References: N/A

    Published: 14 Jan 2022
    4.4
    Medium

    CVE-2021-39680

    Last Modified: 21 Nov 2024

    In sec_SHA256_Transform of sha256_core.c, there is a possible way to read heap data due to uninitialized data. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-197965864References: N/A

    Published: 14 Jan 2022
    7
    High

    CVE-2021-39679

    Last Modified: 21 Nov 2024

    In init of vendor_graphicbuffer_meta.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-188745089References: N/A

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39678

    Last Modified: 21 Nov 2024

    In <TBD> of <TBD>, there is a possible bypass of Factory Reset Protection due to <TBD>. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-171742549References: N/A

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-39659

    Last Modified: 21 Nov 2024

    In sortSimPhoneAccountsForEmergency of CreateConnectionProcessor.java, there is a possible prevention of access to emergency calling due to an unhandled exception. In rare instances, this could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-208267659

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39634

    Last Modified: 21 Nov 2024

    In fs/eventpoll.c, there is a possible use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-204450605References: Upstream kernel

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-39633

    Last Modified: 21 Nov 2024

    In gre_handle_offloads of ip_gre.c, there is a possible page fault due to an invalid memory access. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150694665References: Upstream kernel

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39632

    Last Modified: 21 Nov 2024

    In inotify_cb of events.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-202159709

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39630

    Last Modified: 21 Nov 2024

    In executeRequest of OverlayManagerService.java, there is a possible way to control fabricated overlays from adb shell due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-202768292

    Published: 14 Jan 2022
    7
    High

    CVE-2021-39629

    Last Modified: 21 Nov 2024

    In phTmlNfc_Init and phTmlNfc_CleanUp of phTmlNfc.cc, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-197353344

    Published: 14 Jan 2022
    3.3
    Low

    CVE-2021-39628

    Last Modified: 21 Nov 2024

    In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-189575031

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39627

    Last Modified: 21 Nov 2024

    In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-185126549

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39626

    Last Modified: 21 Nov 2024

    In onAttach of ConnectedDeviceDashboardFragment.java, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege in Bluetooth settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194695497

    Published: 14 Jan 2022
    7.3
    High

    CVE-2021-39625

    Last Modified: 21 Nov 2024

    In showCarrierAppInstallationNotification of EuiccNotificationManager.java, there is a possible way to gain an access to MediaProvider content due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194695347

    Published: 14 Jan 2022
    9.8
    Critical

    CVE-2021-39623

    Last Modified: 21 Nov 2024

    In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-194105348

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39622

    Last Modified: 21 Nov 2024

    In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12Android ID: A-192663648

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39621

    Last Modified: 21 Nov 2024

    In sendLegacyVoicemailNotification of LegacyModeSmsHandler.java, there is a possible permissions bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-185126319

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39620

    Last Modified: 21 Nov 2024

    In ipcSetDataReference of Parcel.cpp, there is a possible way to corrupt memory due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12Android ID: A-203847542

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-39618

    Last Modified: 21 Nov 2024

    In multiple methods of EuiccNotificationManager.java, there is a possible way to install existing packages without user consent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196855999

    Published: 14 Jan 2022
    9.8
    Critical

    CVE-2021-1049

    Last Modified: 21 Nov 2024

    Hacker one bug ID: 1343975Product: AndroidVersions: Android SoCAndroid ID: A-204256722

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-0959

    Last Modified: 21 Nov 2024

    In jit_memory_region.cc, there is a possible bypass of memory restrictions due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-200284993

    Published: 14 Jan 2022
    7.8
    High

    CVE-2022-21137

    Last Modified: 16 Apr 2025

    Omron CX-One Versions 4.60 and prior are vulnerable to a stack-based buffer overflow while processing specific project files, which may allow an attacker to execute arbitrary code.

    Published: 14 Jan 2022
    5.3
    Medium

    CVE-2021-36199

    Last Modified: 21 Nov 2024

    Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-23138

    Last Modified: 16 Apr 2025

    WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-23157

    Last Modified: 16 Apr 2025

    WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.

    Published: 14 Jan 2022
    7.5
    High

    CVE-2021-45769

    Last Modified: 21 Nov 2024

    A NULL pointer dereference in AcseConnection_parseMessage at src/mms/iso_acse/acse.c of libiec61850 v1.5.0 can lead to a segmentation fault or application crash.

    Published: 14 Jan 2022
    2.5
    Low

    CVE-2021-44714

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In affected versions, this warning message does not include custom protocols when used by the sender. User interaction is required to abuse this vulnerability as they would need to click 'allow' on the warning message of a malicious file.

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-44710

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-44705

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2022
    7.8
    High

    CVE-2021-44703

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a stack buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-45067

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-44712

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2022
    5.5
    Medium

    CVE-2021-44713

    Last Modified: 21 Nov 2024

    Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in application denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Jan 2022