Latest CVE Feed
-
9.8
CRITICALCVE-2021-27646
Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to execute arbitrary code via crafted web requests.... Read more
- EPSS Score: %2.20
- Published: Mar. 12, 2021
- Modified: Jan. 14, 2025
-
9.8
CRITICALCVE-2014-3600
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.... Read more
Affected Products : activemq- EPSS Score: %0.53
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2021-27706
Buffer Overflow in Tenda G1 and G3 routers with firmware version V15.11.0.17(9502)_CN allows remote attackers to execute arbitrary code via a crafted action/"IPMacBindIndex "request. This occurs because the "formIPMacBindDel" function directly passes the ... Read more
- EPSS Score: %3.11
- Published: Apr. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27663
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.... Read more
- EPSS Score: %0.61
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27514
EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).... Read more
Affected Products : eyesofnetwork- EPSS Score: %13.67
- Published: Feb. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27610
SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does not create information about internal and external RFC user in consistent and distinguished format, which could lead to improper authe... Read more
- EPSS Score: %0.55
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27439
TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of effective memory allocation size. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected beh... Read more
Affected Products : tencentos-tiny- EPSS Score: %1.05
- Published: May. 03, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27428
GE UR IED firmware versions prior to version 8.1x supports upgrading firmware using UR Setup configuration tool – Enervista UR Setup. This UR Setup tool validates the authenticity and integrity of firmware file before uploading the UR IED. An illegitimate... Read more
- EPSS Score: %0.24
- Published: Mar. 23, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27384
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMA... Read more
Affected Products : sinamics_sl150_firmware sinamics_sm150_firmware sinamics_sm150i_firmware simatic_wincc_runtime_advanced sinamics_gh150_firmware sinamics_gl150_firmware sinamics_gm150_firmware sinamics_sm120_firmware sinamics_sh150_firmware simatic_hmi_comfort_outdoor_panels_7\"_firmware +25 more products- EPSS Score: %1.43
- Published: May. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27440
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).... Read more
- EPSS Score: %0.27
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27389
A vulnerability has been identified in Opcenter Quality (All versions < V12.2), QMS Automotive (All versions < V12.30). A private sign key is shipped with the product without adequate protection.... Read more
- EPSS Score: %0.41
- Published: Apr. 22, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27451
Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an attacker to gain access to the device.... Read more
Affected Products : amegaview- EPSS Score: %0.21
- Published: Dec. 21, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27341
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.... Read more
Affected Products : opensis- EPSS Score: %0.84
- Published: Sep. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-7390
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct requ... Read more
Affected Products : manageengine_desktop_central- EPSS Score: %66.78
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27376
An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain versions of the standard library because it relies on a direct cast of std::net::SocketAddrV4 and std::net::SocketAddrV6 data structures.... Read more
Affected Products : nb-connect- EPSS Score: %0.43
- Published: Feb. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2024-49747
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploita... Read more
Affected Products : android- Published: Jan. 21, 2025
- Modified: Apr. 22, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2021-27236
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution.... Read more
Affected Products : voice- EPSS Score: %1.90
- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-5017
SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : web_gateway- EPSS Score: %24.96
- Published: Jun. 18, 2014
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2021-27193
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.... Read more
- EPSS Score: %1.18
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-27185
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.... Read more
Affected Products : samba-client- EPSS Score: %11.18
- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024