Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-22904 Unspecified vulnerability in Rubyonrails Rails
The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability in the Token Authentication logic in Action Controller due to a too permissive regular expression.
network
low complexity
rubyonrails
7.5
2021-06-11 CVE-2021-23140 Unspecified vulnerability in Gallagher Command Centre
Improper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised Command Centre Operator.
network
low complexity
gallagher
8.8
2021-06-11 CVE-2021-23205 Improper Encoding or Escaping of Output vulnerability in Gallagher Command Centre
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator to alter the configuration of Controllers and other hardware items beyond their privilege.
network
low complexity
gallagher CWE-116
8.1
2021-06-11 CVE-2021-28210 Uncontrolled Recursion vulnerability in Tianocore Edk2
An unlimited recursion in DxeCore in EDK II.
local
low complexity
tianocore CWE-674
7.8
2021-06-11 CVE-2021-28213 Unspecified vulnerability in Tianocore Edk2 201905
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
network
low complexity
tianocore
7.5
2021-06-11 CVE-2021-25388 Improper Validation of Integrity Check Value vulnerability in Google Android 11.0
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
local
low complexity
google CWE-354
7.1
2021-06-11 CVE-2021-25399 Unspecified vulnerability in Samsung Smart Manager
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.
local
low complexity
samsung
7.1
2021-06-11 CVE-2021-25400 Unspecified vulnerability in Samsung Internet 13.2.1.46/13.2.1.70
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
local
low complexity
samsung
7.8
2021-06-11 CVE-2021-25401 Unspecified vulnerability in Samsung Health
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.
local
low complexity
samsung
7.8
2021-06-11 CVE-2021-25407 Out-of-bounds Write vulnerability in Google Android 10.0/11.0/9.0
A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.
local
low complexity
google CWE-787
7.8