Total
9649 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2021-25519 | 1 Google | 1 Android | 2024-11-21 | 4 Medium |
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission. | ||||
CVE-2021-25486 | 1 Google | 1 Android | 2024-11-21 | 2.5 Low |
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log. | ||||
CVE-2021-25464 | 1 Samsung | 1 Capture | 2024-11-21 | 3.3 Low |
An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak. | ||||
CVE-2021-25432 | 2 Google, Samsung | 2 Android, Samsung Members | 2024-11-21 | 3.3 Low |
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data. | ||||
CVE-2021-25426 | 1 Google | 1 Android | 2024-11-21 | 7.5 High |
Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted applications to access Message files. | ||||
CVE-2021-25403 | 2 Google, Samsung | 2 Android, Account | 2024-11-21 | 3.3 Low |
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component. | ||||
CVE-2021-25392 | 1 Google | 1 Android | 2024-11-21 | 4 Medium |
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path. | ||||
CVE-2021-25376 | 1 Samsung | 1 Email | 2024-11-21 | 3.1 Low |
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed. | ||||
CVE-2021-25375 | 1 Samsung | 1 Email | 2024-11-21 | 6.5 Medium |
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment. | ||||
CVE-2021-25364 | 1 Google | 1 Android | 2024-11-21 | 4 Medium |
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information. | ||||
CVE-2021-25357 | 1 Google | 1 Android | 2024-11-21 | 5.6 Medium |
A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.4.81.1 in Android Q(10,0), and 3.6.80.7 in Android R(11.0) allows unprivileged applications to access contact information. | ||||
CVE-2021-25350 | 2 Google, Samsung | 2 Android, Account | 2024-11-21 | 2 Low |
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log. | ||||
CVE-2021-25333 | 1 Samsung | 1 Pay Mini | 2024-11-21 | 3.2 Low |
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code. | ||||
CVE-2021-25332 | 1 Samsung | 1 Pay Mini | 2024-11-21 | 3.2 Low |
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition. | ||||
CVE-2021-25331 | 1 Samsung | 1 Pay Mini | 2024-11-21 | 3.2 Low |
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition. | ||||
CVE-2021-25118 | 1 Yoast | 1 Yoast Seo | 2024-11-21 | 5.3 Medium |
The Yoast SEO WordPress plugin (from versions 16.7 until 17.2) discloses the full internal path of featured images in posts via the wp/v2/posts REST endpoints which could help an attacker identify other vulnerabilities or help during the exploitation of other identified vulnerabilities. | ||||
CVE-2021-25110 | 1 Futuriowp | 1 Futurio Extra | 2024-11-21 | 4.3 Medium |
The Futurio Extra WordPress plugin before 1.6.3 allows any logged in user, such as subscriber, to extract any other user's email address. | ||||
CVE-2021-24948 | 1 Posimyth | 1 The Plus Addons For Elementor | 2024-11-21 | 7.5 High |
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts | ||||
CVE-2021-24945 | 1 Likebtn | 1 Like Button Rating | 2024-11-21 | 8.0 High |
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog. | ||||
CVE-2021-24661 | 1 Wpxpo | 1 Postx - Gutenberg Blocks For Post Grid | 2024-11-21 | 4.3 Medium |
The PostX – Gutenberg Blocks for Post Grid WordPress plugin before 2.4.10, with Saved Templates Addon enabled, allows users with Contributor roles or higher to read password-protected or private post contents the user is otherwise unable to read, given the post ID. |