Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24280 1 Apache 1 Pulsar 2022-09-23 N/A 6.5 MEDIUM
Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to open TCP/IP connections to any IP address and port that the Pulsar Proxy can connect to. An attacker could use this as a way for DoS attacks that originate from the Pulsar Proxy's IP address. It hasn’t been detected that the Pulsar Proxy authentication can be bypassed. The attacker will have to have a valid token to a properly secured Pulsar Proxy. This issue affects Apache Pulsar Proxy versions 2.7.0 to 2.7.4; 2.8.0 to 2.8.2; 2.9.0 to 2.9.1; 2.6.4 and earlier.
CVE-2021-25472 1 Google 1 Android 2022-09-23 2.1 LOW 3.3 LOW
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
CVE-2021-25518 1 Google 1 Android 2022-09-23 4.6 MEDIUM 6.7 MEDIUM
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.
CVE-2021-25489 2 Google, Samsung 2 Android, Exynos 2022-09-23 4.9 MEDIUM 5.5 MEDIUM
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
CVE-2021-25464 1 Samsung 1 Capture 2022-09-23 2.1 LOW 5.5 MEDIUM
An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.
CVE-2021-25361 1 Google 1 Android 2022-09-23 7.2 HIGH 8.8 HIGH
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
CVE-2021-25360 1 Google 1 Android 2022-09-23 7.5 HIGH 9.8 CRITICAL
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVE-2021-25366 1 Samsung 1 Internet 2022-09-23 3.6 LOW 2.9 LOW
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
CVE-2021-25351 2 Google, Samsung 2 Android, Account 2022-09-23 2.1 LOW 2.4 LOW
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
CVE-2021-25340 1 Google 1 Android 2022-09-23 2.1 LOW 2.4 LOW
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
CVE-2021-25387 1 Google 1 Android 2022-09-23 7.5 HIGH 10.0 CRITICAL
An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVE-2021-25386 1 Google 1 Android 2022-09-23 7.5 HIGH 9.8 CRITICAL
An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVE-2021-25385 1 Google 1 Android 2022-09-23 7.5 HIGH 9.8 CRITICAL
An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVE-2021-25383 1 Google 1 Android 2022-09-23 7.5 HIGH 9.8 CRITICAL
An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVE-2021-25378 1 Samsung 1 Smartthings 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.
CVE-2021-25459 1 Google 1 Android 2022-09-23 2.1 LOW 5.5 MEDIUM
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
CVE-2021-25453 1 Google 1 Android 2022-09-23 2.1 LOW 5.5 MEDIUM
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
CVE-2021-25448 1 Samsung 1 Smart Touch Call 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
CVE-2021-25447 1 Samsung 2 Smartthings, Smartthings Firmware 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
CVE-2021-25446 1 Samsung 2 Smartthings, Smartthings Firmware 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.