|
194601
|
5.4 |
MEDIUM
Network
|
publify_project
|
publify
|
In Publify, versions v8.0 to v9.2.4 are vulnerable to stored XSS. A user with a “publisher” role is able to inject and execute arbitrary JavaScript code while creating a page/article.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25974
|
2024-11-21 14:55 |
2021-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194602
|
9.8 |
CRITICAL
Network
|
apostrophecms
|
apostrophecms
|
Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or changing the password, creating a situation in which a device compromised by a third…
|
-
|
CVE-2021-25979
|
2024-11-21 14:55 |
2021-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194603
|
5.4 |
MEDIUM
Network
|
apostrophecms
|
apostrophecms
|
Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that contains malicious JavaScript onto the Images module, which triggers XSS once vie…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25978
|
2024-11-21 14:55 |
2021-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194604
|
7.1 |
HIGH
Local
|
samsung
|
samsung_flow
|
A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.
|
CWE-20
Improper Input Validation
|
CVE-2021-25509
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194605
|
9.8 |
CRITICAL
Network
|
samsung
|
smartthings
|
Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.
|
CWE-269
Improper Privilege Management
|
CVE-2021-25508
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194606
|
5.7 |
MEDIUM
Adjacent
|
samsung
|
samsung_flow
|
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure F…
|
NVD-CWE-Other
|
CVE-2021-25507
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194607
|
5.5 |
MEDIUM
Local
|
samsung
|
health
|
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25506
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194608
|
7.8 |
HIGH
Local
|
samsung
|
samsung_pass
|
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
|
CWE-287
Improper Authentication
|
CVE-2021-25505
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194609
|
4.0 |
MEDIUM
Local
|
samsung
|
group_sharing
|
Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
|
NVD-CWE-Other
|
CVE-2021-25504
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194610
|
6.7 |
MEDIUM
Local
|
google
|
android
|
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
|
CWE-20
Improper Input Validation
|
CVE-2021-25503
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|