CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2021-23136

    Last Modified: 21 Nov 2024

    Improper Authorization vulnerability in Gallagher Command Centre Server allows macro overrides to be performed by an unprivileged Command Centre Operator. This issue affects: Gallagher Command Centre 8.40 versions prior to 8.40.1888 (MR3); 8.30 versions prior to 8.30.1359 (MR3); 8.20 versions prior to 8.20.1259 (MR5); version 8.10 and prior versions.

    Published: 11 Jun 2021
    7.7
    High

    CVE-2021-22181

    Last Modified: 21 Nov 2024

    A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

    Published: 11 Jun 2021
    4.3
    Medium

    CVE-2021-22769

    Last Modified: 29 Jun 2026

    A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.

    Published: 11 Jun 2021
    9.8
    Critical

    CVE-2021-22768

    Last Modified: 29 May 2026

    A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22767

    Published: 11 Jun 2021
    9.8
    Critical

    CVE-2021-22765

    Last Modified: 29 May 2026

    A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet

    Published: 11 Jun 2021
    5.3
    Medium

    CVE-2021-22764

    Last Modified: 29 May 2026

    A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.

    Published: 11 Jun 2021
    9.8
    Critical

    CVE-2021-22763

    Last Modified: 29 May 2026

    A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22762

    Last Modified: 21 Nov 2024

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition.

    Published: 11 Jun 2021
    9.8
    Critical

    CVE-2021-22767

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276

    Published: 11 Jun 2021
    7.5
    High

    CVE-2021-22766

    Last Modified: 21 Nov 2024

    A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22753

    Last Modified: 21 Nov 2024

    A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22754

    Last Modified: 21 Nov 2024

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22755

    Last Modified: 21 Nov 2024

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22756

    Last Modified: 21 Nov 2024

    A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data validation, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22757

    Last Modified: 21 Nov 2024

    A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied input data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22758

    Last Modified: 21 Nov 2024

    A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack validation of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22760

    Last Modified: 21 Nov 2024

    A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22761

    Last Modified: 21 Nov 2024

    A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code e+F15xecution due to missing length check on user supplied data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22752

    Last Modified: 21 Nov 2024

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22759

    Last Modified: 21 Nov 2024

    A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22750

    Last Modified: 21 Nov 2024

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-22751

    Last Modified: 21 Nov 2024

    A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.

    Published: 11 Jun 2021
    5.3
    Medium

    CVE-2021-22749

    Last Modified: 21 Nov 2024

    A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is sent to the web server of the module.

    Published: 11 Jun 2021
    6.8
    Medium

    CVE-2021-22175

    Last Modified: 19 Feb 2026

    When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is disabled

    Published: 11 Jun 2021
    6.1
    Medium

    CVE-2020-13688

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in l Drupal Core allows an attacker could leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.X versions prior to 8.8.10; 8.9.X versions prior to 8.9.6; 9.0.X versions prior to 9.0.6.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2020-13663

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-28687

    Last Modified: 21 Nov 2024

    HVM soft-reset crashes toolstack libxl requires all data structures passed across its public interface to be initialized before use and disposed of afterwards by calling a specific set of functions. Many internal data structures also require this initialize / dispose discipline, but not all of them. When the "soft reset" feature was implemented, the libxl__domain_suspend_state structure didn't require any initialization or disposal. At some point later, an initialization function was introduced for the structure; but the "soft reset" path wasn't refactored to call the initialization function. When a guest nwo initiates a "soft reboot", uninitialized data structure leads to an assert() when later code finds the structure in an unexpected state. The effect of this is to crash the process monitoring the guest. How this affects the system depends on the structure of the toolstack. For xl, this will have no security-relevant effect: every VM has its own independent monitoring process, which contains no state. The domain in question will hang in a crashed state, but can be destroyed by `xl destroy` just like any other non-cooperating domain. For daemon-based toolstacks linked against libxl, such as libvirt, this will crash the toolstack, losing the state of any in-progress operations (localized DoS), and preventing further administrator operations unless the daemon is configured to restart automatically (system-wide DoS). If crashes "leak" resources, then repeated crashes could use up resources, also causing a system-wide DoS.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-28689

    Last Modified: 21 Nov 2024

    x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it to implement paravirtualisation, Xen's novel approach to virtualization. In AMD64, Xen had to use a different implementation approach, so Xen does not use ring 1 to support 64-bit guests. With the focus now being on 64-bit systems, and the availability of explicit hardware support for virtualization, fixing speculation issues in ring 1 is not a priority for processor companies. Indirect Branch Restricted Speculation (IBRS) is an architectural x86 extension put together to combat speculative execution sidechannel attacks, including Spectre v2. It was retrofitted in microcode to existing CPUs. For more details on Spectre v2, see: http://xenbits.xen.org/xsa/advisory-254.html However, IBRS does not architecturally protect ring 0 from predictions learnt in ring 1. For more details, see: https://software.intel.com/security-software-guidance/deep-dives/deep-dive-indirect-branch-restricted-speculation Similar situations may exist with other mitigations for other kinds of speculative execution attacks. The situation is quite likely to be similar for speculative execution attacks which have yet to be discovered, disclosed, or mitigated.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25405

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access local files.

    Published: 11 Jun 2021
    7.1
    High

    CVE-2021-25399

    Last Modified: 21 Nov 2024

    Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25400

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25401

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.

    Published: 11 Jun 2021
    3.3
    Low

    CVE-2021-25402

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.

    Published: 11 Jun 2021
    3.3
    Low

    CVE-2021-25403

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.

    Published: 11 Jun 2021
    6.5
    Medium

    CVE-2021-25406

    Last Modified: 21 Nov 2024

    Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

    Published: 11 Jun 2021
    3.3
    Low

    CVE-2021-25404

    Last Modified: 21 Nov 2024

    Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.

    Published: 11 Jun 2021
    6.4
    Medium

    CVE-2021-25395

    Last Modified: 30 Oct 2025

    A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

    Published: 11 Jun 2021
    6.4
    Medium

    CVE-2021-25394

    Last Modified: 30 Oct 2025

    A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

    Published: 11 Jun 2021
    6.8
    Medium

    CVE-2021-25397

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

    Published: 11 Jun 2021
    4
    Medium

    CVE-2021-25390

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

    Published: 11 Jun 2021
    4
    Medium

    CVE-2021-25391

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

    Published: 11 Jun 2021
    4
    Medium

    CVE-2021-25392

    Last Modified: 21 Nov 2024

    Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.

    Published: 11 Jun 2021
    6.6
    Medium

    CVE-2021-25393

    Last Modified: 21 Nov 2024

    Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.

    Published: 11 Jun 2021
    3.3
    Low

    CVE-2021-25398

    Last Modified: 21 Nov 2024

    Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.

    Published: 11 Jun 2021
    6.7
    Medium

    CVE-2021-25396

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.

    Published: 11 Jun 2021
    2.3
    Low

    CVE-2021-25389

    Last Modified: 21 Nov 2024

    Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

    Published: 11 Jun 2021
    9
    Critical

    CVE-2021-25383

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

    Published: 11 Jun 2021
    9
    Critical

    CVE-2021-25384

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

    Published: 11 Jun 2021
    9
    Critical

    CVE-2021-25385

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

    Published: 11 Jun 2021
    9
    Critical

    CVE-2021-25386

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

    Published: 11 Jun 2021