Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25466 1 Samsung 1 Internet 2021-09-23 5.0 MEDIUM 5.9 MEDIUM
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
CVE-2021-24726 1 Wpsimplebookingcalendar 1 Wp Simple Booking Calendar 2021-09-23 6.5 MEDIUM 8.8 HIGH
The WP Simple Booking Calendar WordPress plugin before 2.0.6 did not escape, validate or sanitise the orderby parameter in its Search Calendars action, before using it in a SQL statement, leading to an authenticated SQL injection issue
CVE-2021-38092 1 Ffmpeg 1 Ffmpeg 2021-09-23 6.8 MEDIUM 8.8 HIGH
Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
CVE-2021-38091 1 Ffmpeg 1 Ffmpeg 2021-09-23 6.8 MEDIUM 8.8 HIGH
Integer Overflow vulnerability in function filter16_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
CVE-2021-38090 1 Ffmpeg 1 Ffmpeg 2021-09-23 6.8 MEDIUM 8.8 HIGH
Integer Overflow vulnerability in function filter16_roberts in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
CVE-2021-38094 1 Ffmpeg 1 Ffmpeg 2021-09-23 6.8 MEDIUM 8.8 HIGH
Integer Overflow vulnerability in function filter_sobel in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
CVE-2021-38093 1 Ffmpeg 1 Ffmpeg 2021-09-23 6.8 MEDIUM 8.8 HIGH
Integer Overflow vulnerability in function filter_robert in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.
CVE-2021-24727 1 Stopbadbots 1 Block And Stop Bad Bots 2021-09-23 6.5 MEDIUM 8.8 HIGH
The StopBadBots WordPress plugin before 6.60 did not validate or escape the order and orderby GET parameter in some of its admin dashboard pages, leading to Authenticated SQL Injections
CVE-2021-24605 1 Custom Post View Generator Project 1 Custom Post View Generator 2021-09-23 3.5 LOW 5.4 MEDIUM
The create_post_page AJAX action of the Custom Post View Generator WordPress plugin through 0.4.6 (available to authenticated user) does not sanitise or escape user input before outputting it back in the response, leading to a Reflected Cross-Site issue
CVE-2021-24614 1 Oz-plugin 1 Book Appointment Online 2021-09-23 3.5 LOW 4.8 MEDIUM
The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-24619 1 Evona 1 Per Page Add To Head 2021-09-23 3.5 LOW 4.8 MEDIUM
The Per page add to head WordPress plugin through 1.4.4 does not properly sanitise one of its setting, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
CVE-2021-24621 1 Stratospheredigital 1 Wp Courses Lms 2021-09-23 3.5 LOW 4.8 MEDIUM
The WP Courses LMS WordPress plugin before 2.0.44 does not sanitise its Video Embed Code, allowing malicious code to be injected in it by high privilege users, even when the unfiltered_html capability is disallowed, which could lead to Stored Cross-Site Scripting issues
CVE-2021-25462 1 Google 1 Android 2021-09-23 2.1 LOW 5.5 MEDIUM
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
CVE-2021-28271 1 Soyal 3 701clientsql, 701server, 701serversql 2021-09-23 6.5 MEDIUM 8.8 HIGH
Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group.
CVE-2021-24623 1 Ticket-system 1 Wordpress Advanced Ticket System 2021-09-23 3.5 LOW 4.8 MEDIUM
The WordPress Advanced Ticket System, Elite Support Helpdesk WordPress plugin before 1.0.64 does not sanitize or escape form values before saving to the database or when outputting, which allows high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
CVE-2021-25458 1 Google 1 Android 2021-09-23 2.1 LOW 5.5 MEDIUM
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
CVE-2021-24508 1 Smashballoon 1 Smash Balloon Social Post Feed 2021-09-23 4.3 MEDIUM 6.1 MEDIUM
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
CVE-2020-8216 1 Pulsesecure 2 Pulse Connect Secure, Pulse Policy Secure 2021-09-23 4.0 MEDIUM 4.3 MEDIUM
An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.
CVE-2021-24493 1 Ingenesis 1 Shopp 2021-09-23 7.5 HIGH 9.8 CRITICAL
The shopp_upload_file AJAX action of the Shopp WordPress plugin through 1.4, available to both unauthenticated and authenticated user does not have any security measure in place to prevent upload of malicious files, such as PHP, allowing unauthenticated users to upload arbitrary files and leading to RCE
CVE-2020-8232 1 Ui 12 Edgeswitch Firmware, Ep-16-xg, Ep-s16 and 9 more 2021-09-23 4.0 MEDIUM 6.5 MEDIUM
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.