Vulnerabilities (CVE)

Filtered by CWE-20
Total 13258 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26321 1 Amd 114 Epyc 7232p, Epyc 7232p Firmware, Epyc 7251 and 111 more 2026-06-17 4.9 MEDIUM 5.5 MEDIUM
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
CVE-2021-26316 1 Amd 294 Athlon 3050ge, Athlon 3050ge Firmware, Athlon 3150g and 291 more 2026-06-17 N/A 7.8 HIGH
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
CVE-2021-26251 1 Intel 1 Openvino 2026-06-17 N/A 5.3 MEDIUM
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.
CVE-2021-26036 1 Joomla 1 Joomla\! 2026-06-17 5.0 MEDIUM 7.5 HIGH
An issue was discovered in Joomla! 2.5.0 through 3.9.27. Missing validation of input could lead to a broken usergroups table.
CVE-2021-25748 1 Kubernetes 1 Ingress-nginx 2026-06-17 N/A 7.6 HIGH
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
CVE-2021-25746 1 Kubernetes 1 Ingress-nginx 2026-06-17 5.5 MEDIUM 7.6 HIGH
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
CVE-2021-25745 1 Kubernetes 1 Ingress-nginx 2026-06-17 5.5 MEDIUM 7.6 HIGH
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
CVE-2021-25742 2 Kubernetes, Netapp 2 Ingress-nginx, Trident 2026-06-17 5.5 MEDIUM 7.6 HIGH
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
CVE-2021-25741 1 Kubernetes 1 Kubernetes 2026-06-17 5.5 MEDIUM 8.8 HIGH
A security issue was discovered in Kubernetes where a user may be able to create a container with subpath volume mounts to access files & directories outside of the volume, including on the host filesystem.
CVE-2021-25738 1 Kubernetes 1 Java 2026-06-17 4.6 MEDIUM 6.7 MEDIUM
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution.
CVE-2021-25684 1 Canonical 1 Apport 2026-06-17 4.6 MEDIUM 8.8 HIGH
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
CVE-2021-25683 1 Canonical 1 Apport 2026-06-17 7.2 HIGH 8.8 HIGH
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
CVE-2021-25682 1 Canonical 1 Apport 2026-06-17 7.2 HIGH 8.8 HIGH
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
CVE-2021-25520 1 Samsung 1 Internet 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
CVE-2021-25517 1 Google 1 Android 2026-06-17 4.6 MEDIUM 7.7 HIGH
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.
CVE-2021-25512 1 Google 1 Android 2026-06-17 4.6 MEDIUM 6.1 MEDIUM
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.
CVE-2021-25511 1 Google 1 Android 2026-06-17 4.6 MEDIUM 6.3 MEDIUM
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.
CVE-2021-25510 1 Google 1 Android 2026-06-17 4.6 MEDIUM 5.3 MEDIUM
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.
CVE-2021-25509 1 Samsung 1 Samsung Flow 2026-06-17 3.6 LOW 5.9 MEDIUM
A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.
CVE-2021-25504 1 Samsung 1 Group Sharing 2026-06-17 2.1 LOW 4.0 MEDIUM
Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.