CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2021-41450

    Last Modified: 21 Nov 2024

    An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.

    Published: 8 Dec 2021
    7.2
    High

    CVE-2021-40861

    Last Modified: 21 Nov 2024

    A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allows an attacker to execute arbitrary SQL queries via the value attribute, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

    Published: 8 Dec 2021
    7.2
    High

    CVE-2021-40860

    Last Modified: 21 Nov 2024

    A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.11 allows an attacker to execute arbitrary SQL queries via the ql_expression parameter, with which all data in the database can be extracted and OS command execution is possible depending on the permissions and/or database engine.

    Published: 8 Dec 2021
    7
    High

    CVE-2021-42835

    Last Modified: 21 Nov 2024

    An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute code from a path of his choice (local, or remote via SMB) because of a TOCTOU race condition. This code execution is in the context of the Plex update service (which runs as SYSTEM).

    Published: 8 Dec 2021
    3.8
    Low

    CVE-2021-25527

    Last Modified: 21 Nov 2024

    Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.

    Published: 8 Dec 2021
    4
    Medium

    CVE-2021-25526

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.

    Published: 8 Dec 2021
    2
    Low

    CVE-2021-25525

    Last Modified: 21 Nov 2024

    Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.

    Published: 8 Dec 2021
    4
    Medium

    CVE-2021-25524

    Last Modified: 21 Nov 2024

    Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

    Published: 8 Dec 2021
    4
    Medium

    CVE-2021-25523

    Last Modified: 21 Nov 2024

    Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-25522

    Last Modified: 21 Nov 2024

    Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.

    Published: 8 Dec 2021
    4
    Medium

    CVE-2021-25521

    Last Modified: 21 Nov 2024

    Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

    Published: 8 Dec 2021
    5.9
    Medium

    CVE-2021-25520

    Last Modified: 21 Nov 2024

    Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.

    Published: 8 Dec 2021
    4
    Medium

    CVE-2021-25519

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.

    Published: 8 Dec 2021
    6.4
    Medium

    CVE-2021-25518

    Last Modified: 21 Nov 2024

    An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

    Published: 8 Dec 2021
    7.7
    High

    CVE-2021-25517

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.

    Published: 8 Dec 2021
    6.4
    Medium

    CVE-2021-25516

    Last Modified: 21 Nov 2024

    An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

    Published: 8 Dec 2021
    4
    Medium

    CVE-2021-25515

    Last Modified: 21 Nov 2024

    An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

    Published: 8 Dec 2021
    3.3
    Low

    CVE-2021-25514

    Last Modified: 21 Nov 2024

    An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.

    Published: 8 Dec 2021
    2.4
    Low

    CVE-2021-25513

    Last Modified: 21 Nov 2024

    An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-25512

    Last Modified: 21 Nov 2024

    An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

    Published: 8 Dec 2021
    6.3
    Medium

    CVE-2021-25511

    Last Modified: 21 Nov 2024

    An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-25510

    Last Modified: 21 Nov 2024

    An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37097

    Last Modified: 21 Nov 2024

    There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-37093

    Last Modified: 21 Nov 2024

    There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers steal short messages.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37092

    Last Modified: 21 Nov 2024

    There is a Incomplete Cleanup vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37075

    Last Modified: 21 Nov 2024

    There is a Credentials Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to confidentiality affected.

    Published: 8 Dec 2021
    8.1
    High

    CVE-2021-37074

    Last Modified: 21 Nov 2024

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to the user root privilege escalation.

    Published: 8 Dec 2021
    7.4
    High

    CVE-2021-37069

    Last Modified: 21 Nov 2024

    There is a Race Condition vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to availability affected.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37054

    Last Modified: 21 Nov 2024

    There is an Identity spoofing and authentication bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37053

    Last Modified: 21 Nov 2024

    There is a Service logic vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause WLAN DoS.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37052

    Last Modified: 21 Nov 2024

    There is an Exception log vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause address information leakage.

    Published: 8 Dec 2021
    9.1
    Critical

    CVE-2021-37051

    Last Modified: 21 Nov 2024

    There is an Out-of-bounds read vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds memory access.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37050

    Last Modified: 21 Nov 2024

    There is a Missing sensitive data encryption vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-37049

    Last Modified: 21 Nov 2024

    There is a Heap-based buffer overflow vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may rewrite the memory of adjacent objects.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-37045

    Last Modified: 21 Nov 2024

    There is an UAF vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart unexpectedly and the kernel-mode code to be executed.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37044

    Last Modified: 21 Nov 2024

    There is a Permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.

    Published: 8 Dec 2021
    9.8
    Critical

    CVE-2021-37040

    Last Modified: 21 Nov 2024

    There is a Parameter injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause privilege escalation of files after CIFS share mounting.

    Published: 8 Dec 2021
    6.5
    Medium

    CVE-2021-37039

    Last Modified: 21 Nov 2024

    There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause Bluetooth DoS.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-37037

    Last Modified: 21 Nov 2024

    There is an Invalid address access vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart.

    Published: 8 Dec 2021
    5.3
    Medium

    CVE-2021-41013

    Last Modified: 21 Nov 2024

    An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-36188

    Last Modified: 21 Nov 2024

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted GET parameters in requests to login and error handlers

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-43063

    Last Modified: 21 Nov 2024

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP GET requests to the login webpage.

    Published: 8 Dec 2021
    5.5
    Medium

    CVE-2021-36190

    Last Modified: 21 Nov 2024

    A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to access protected hosts via crafted HTTP requests.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-41014

    Last Modified: 21 Nov 2024

    A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon unresponsive via huge HTTP packets

    Published: 8 Dec 2021
    4.1
    Medium

    CVE-2021-36191

    Last Modified: 21 Nov 2024

    A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers

    Published: 8 Dec 2021
    7.3
    High

    CVE-2021-41027

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.

    Published: 8 Dec 2021
    6.1
    Medium

    CVE-2021-41015

    Last Modified: 21 Nov 2024

    A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler

    Published: 8 Dec 2021
    4.3
    Medium

    CVE-2021-43064

    Last Modified: 21 Nov 2024

    A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.

    Published: 8 Dec 2021
    8.1
    High

    CVE-2021-26109

    Last Modified: 21 Nov 2024

    An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to corrupt control data on the heap via specifically crafted requests to SSLVPN, resulting in potentially arbitrary code execution.

    Published: 8 Dec 2021
    7.5
    High

    CVE-2021-26108

    Last Modified: 21 Nov 2024

    A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engineering.

    Published: 8 Dec 2021