Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2021
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
CVSS Score
9.0
EPSS Score
0.003
Published
2021-04-09
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
CVSS Score
7.9
EPSS Score
0.0
Published
2021-04-09
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
CVSS Score
6.8
EPSS Score
0.0
Published
2021-04-09
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.
CVSS Score
6.8
EPSS Score
0.0
Published
2021-04-09
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
CVSS Score
4.0
EPSS Score
0.0
Published
2021-04-09
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
CVSS Score
5.9
EPSS Score
0.0
Published
2021-04-09
An exploitable SQL injection vulnerability exists in the "access_rules/rules_form" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
CVSS Score
5.4
EPSS Score
0.034
Published
2021-04-09
An exploitable SQL injection vulnerability exists in "global_lists/choices" page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability, this can be done either with administrator credentials or through cross-site request forgery.
CVSS Score
5.4
EPSS Score
0.032
Published
2021-04-09
Cross Site Scripting (XSS) vulnerability in subrion CMS Version <= 4.2.1 allows remote attackers to execute arbitrary web script via the "payment gateway" column on transactions tab.
CVSS Score
6.1
EPSS Score
0.004
Published
2021-04-09
Cross Site Scripting (XSS) vulnerability in the Larsens Calender plugin Version <= 1.2 for WordPress allows remote attackers to execute arbitrary web script via the "titel" column on the "Eintrage hinzufugen" tab.
CVSS Score
5.4
EPSS Score
0.001
Published
2021-04-09


Contact Us

Shodan ® - All rights reserved