|
196601
|
4.3 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an…
|
CWE-863
Incorrect Authorization
|
CVE-2021-25954
|
2024-11-21 14:55 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196602
|
5.3 |
MEDIUM
Network
|
samsung
|
smart_touch_call
|
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
|
NVD-CWE-Other
|
CVE-2021-25448
|
2024-11-21 14:55 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196603
|
5.3 |
MEDIUM
Network
|
samsung
|
smartthings_firmware
|
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
|
NVD-CWE-Other
|
CVE-2021-25447
|
2024-11-21 14:55 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196604
|
5.3 |
MEDIUM
Network
|
samsung
|
smartthings_firmware
|
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
|
NVD-CWE-Other
|
CVE-2021-25446
|
2024-11-21 14:55 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196605
|
5.3 |
MEDIUM
Network
|
samsung
|
internet
|
Unprotected component vulnerability in Samsung Internet prior to version 14.2 allows untrusted application to access internal files in Samsung Internet.
|
CWE-287
Improper Authentication
|
CVE-2021-25445
|
2024-11-21 14:55 |
2021-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196606
|
8.8 |
HIGH
Network
|
fortinet
|
fortisandbox
|
Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifica…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26096
|
2024-11-21 14:55 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196607
|
8.8 |
HIGH
Network
|
fortinet
|
fortisandbox
|
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacke…
|
CWE-78
OS Command
|
CVE-2021-26097
|
2024-11-21 14:55 |
2021-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196608
|
7.5 |
HIGH
Network
|
fortinet
|
fortisandbox
|
An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predi…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-26098
|
2024-11-21 14:55 |
2021-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196609
|
5.3 |
MEDIUM
Network
|
atlassian
|
confluence_server confluence_data_center
|
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authorization Arbitrary File Read vulnerability in the /s/ endpoint. The affected versio…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2021-26085
|
2024-11-21 14:55 |
2021-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196610
|
7.5 |
HIGH
Network
|
videolan
|
vlc_media_player
|
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-25804
|
2024-11-21 14:55 |
2021-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|