CVE Feed

    Dashboard / CVE

    9
    Critical

    CVE-2021-25387

    Last Modified: 21 Nov 2024

    An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.

    Published: 11 Jun 2021
    7.1
    High

    CVE-2021-25388

    Last Modified: 21 Nov 2024

    Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25421

    Last Modified: 21 Nov 2024

    Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25423

    Last Modified: 21 Nov 2024

    Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone via log.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25422

    Last Modified: 21 Nov 2024

    Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-25424

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

    Published: 11 Jun 2021
    5.3
    Medium

    CVE-2021-25425

    Last Modified: 21 Nov 2024

    Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25420

    Last Modified: 21 Nov 2024

    Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25413

    Last Modified: 21 Nov 2024

    Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25414

    Last Modified: 21 Nov 2024

    Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-25415

    Last Modified: 21 Nov 2024

    Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.

    Published: 11 Jun 2021
    6.5
    Medium

    CVE-2021-25416

    Last Modified: 21 Nov 2024

    Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.

    Published: 11 Jun 2021
    7.5
    High

    CVE-2021-25417

    Last Modified: 21 Nov 2024

    Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal storage.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25418

    Last Modified: 21 Nov 2024

    Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

    Published: 11 Jun 2021
    6.5
    Medium

    CVE-2021-25419

    Last Modified: 21 Nov 2024

    Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25412

    Last Modified: 21 Nov 2024

    An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25407

    Last Modified: 21 Nov 2024

    A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-25408

    Last Modified: 21 Nov 2024

    A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

    Published: 11 Jun 2021
    2.4
    Low

    CVE-2021-25409

    Last Modified: 21 Nov 2024

    Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.

    Published: 11 Jun 2021
    7.1
    High

    CVE-2021-25410

    Last Modified: 21 Nov 2024

    Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.

    Published: 11 Jun 2021
    4.4
    Medium

    CVE-2021-25411

    Last Modified: 21 Nov 2024

    Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-29754

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.

    Published: 11 Jun 2021
    3.3
    Low

    CVE-2021-20396

    Last Modified: 21 Nov 2024

    IBM QRadar Analyst Workflow App 1.0 through 1.18.0 for IBM QRadar SIEM allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 196009.

    Published: 11 Jun 2021
    9.1
    Critical

    CVE-2020-5003

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.

    Published: 11 Jun 2021
    5.3
    Medium

    CVE-2021-26993

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to cause a partial Denial of Service (DoS) to the web server.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-26995

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary code.

    Published: 11 Jun 2021
    7.5
    High

    CVE-2021-26996

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover system configuration and application information which may aid in crafting more complex attacks.

    Published: 11 Jun 2021
    6.5
    Medium

    CVE-2021-26997

    Last Modified: 21 Nov 2024

    E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow a remote attacker to discover information via error messaging which may aid in crafting more complex attacks.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-33205

    Last Modified: 21 Nov 2024

    Western Digital EdgeRover before 0.25 has an escalation of privileges vulnerability where a low privileged user could load malicious content into directories with higher privileges, because of how Node.js is used. An attacker can gain admin privileges and carry out malicious activities such as creating a fake library and stealing user credentials.

    Published: 11 Jun 2021
    6.1
    Medium

    CVE-2021-34540

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard.

    Published: 11 Jun 2021
    9.8
    Critical

    CVE-2021-3013

    Last Modified: 21 Nov 2024

    ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working directory via the -z/--search-zip or --pre flag.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-26828

    Last Modified: 4 Dec 2025

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.

    Published: 11 Jun 2021
    5.4
    Medium

    CVE-2021-26829

    Last Modified: 2 Dec 2025

    OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-28814

    Last Modified: 21 Nov 2024

    An improper access control vulnerability has been reported to affect QNAP NAS. If exploited, this vulnerability allows remote attackers to compromise the security of the software. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.4.

    Published: 11 Jun 2021
    7.8
    High

    CVE-2021-28805

    Last Modified: 21 Nov 2024

    Inclusion of sensitive information in the source code has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read application data. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.3 build 20210505 on QSW-M2108-2C; versions prior to 1.0.3 build 20210505 on QSW-M2108-2S; versions prior to 1.0.3 build 20210505 on QSW-M2108R-2C; versions prior to 1.0.12 build 20210506 on QSW-M408.

    Published: 11 Jun 2021
    3.1
    Low

    CVE-2021-28801

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability has been reported to affect certain QNAP switches running QSS. If exploited, this vulnerability allows attackers to read sensitive information on the system. This issue affects: QNAP Systems Inc. QSS versions prior to 1.0.2 build 20210122 on QSW-M2108-2C; versions prior to 1.0.2 build 20210122 on QSW-M2108-2S; versions prior to 1.0.2 build 20210122 on QSW-M2108R-2C.

    Published: 11 Jun 2021
    9.1
    Critical

    CVE-2021-24035

    Last Modified: 3 Sept 2025

    A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-25684

    Last Modified: 3 Nov 2025

    It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-25683

    Last Modified: 21 Nov 2024

    It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.

    Published: 11 Jun 2021
    8.8
    High

    CVE-2021-25682

    Last Modified: 21 Nov 2024

    It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.

    Published: 11 Jun 2021
    7.5
    High

    CVE-2021-28213

    Last Modified: 21 Nov 2024

    Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.

    Published: 11 Jun 2021
    5.9
    Medium

    CVE-2021-3597

    Last Modified: 21 Nov 2024

    A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw affects Undertow versions prior to 2.0.35.SP1, prior to 2.2.6.SP1, prior to 2.2.7.SP1, prior to 2.0.36.SP1, prior to 2.2.9.Final and prior to 2.0.39.Final.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-3605

    Last Modified: 21 Nov 2024

    There's a flaw in OpenEXR's rleUncompress functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.

    Published: 11 Jun 2021
    5.5
    Medium

    CVE-2021-3598

    Last Modified: 21 Nov 2024

    There's a flaw in OpenEXR's ImfDeepScanLineInputFile functionality in versions prior to 3.0.5. An attacker who is able to submit a crafted file to an application linked with OpenEXR could cause an out-of-bounds read. The greatest risk from this flaw is to application availability.

    Published: 11 Jun 2021
    5.4
    Medium

    CVE-2021-23393

    Last Modified: 21 Nov 2024

    This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server other than Werkzeug is used, or the default behaviour of Werkzeug is modified using 'autocorrect_location_header=False.

    Published: 10 Jun 2021
    6.5
    Medium

    CVE-2021-26199

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file.

    Published: 10 Jun 2021
    6.5
    Medium

    CVE-2021-26198

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file.

    Published: 10 Jun 2021
    6.5
    Medium

    CVE-2021-26197

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript 2.4.0. There is a SEGV in main_print_unhandled_exception in main-utils.c file.

    Published: 10 Jun 2021
    8.8
    High

    CVE-2021-26195

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file.

    Published: 10 Jun 2021
    6.5
    Medium

    CVE-2021-26194

    Last Modified: 21 Nov 2024

    An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-helpers.c file.

    Published: 10 Jun 2021