Latest CVE Feed
-
9.3
HIGHCVE-2021-40397
A privilege escalation vulnerability exists in the installation of Advantech WISE-PaaS/OTA Server 3.0.9. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trig... Read more
Affected Products : wise-paas\/ota- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40396
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iService 1.1.7. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger... Read more
Affected Products : deviceon\/iservice- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40394
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code executi... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40393
An out-of-bounds write vulnerability exists in the RS-274X aperture macro variables handling functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and the forked version of Gerbv (commit 71493260). A specially-crafted gerber file can lead to code executi... Read more
- Published: Dec. 22, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40392
An information disclosure vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. Network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to exploit this vulnerability.... Read more
Affected Products : mxview- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40391
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attack... Read more
- Published: Nov. 19, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-40390
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView Series 3.2.4. A specially-crafted HTTP request can lead to unauthorized access. An attacker can send an HTTP request to trigger this vulnerability.... Read more
Affected Products : mxview- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40389
A privilege escalation vulnerability exists in the installation of Advantech DeviceOn/iEdge Server 1.0.2. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to tri... Read more
Affected Products : deviceon\/iedge- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-40388
A privilege escalation vulnerability exists in Advantech SQ Manager Server 1.0.6. A specially-crafted file can be replaced in the system to escalate privileges to NT SYSTEM authority. An attacker can provide a malicious file to trigger this vulnerability.... Read more
Affected Products : sq_manager- Published: Jan. 28, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-40387
An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is authenticated remote code execution.... Read more
Affected Products : unitrends_backup_software- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-40386
Kaseya Unitrends Client/Agent through 10.5,5 allows remote attackers to execute arbitrary code.... Read more
Affected Products : unitrends_backup- Published: Apr. 15, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-40385
An issue was discovered in the server software in Kaseya Unitrends Backup Software before 10.5.5-2. There is a privilege escalation from read-only user to admin.... Read more
Affected Products : unitrends_backup_software- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40382
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allows video screenshot access.... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40381
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows video access.... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40380
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. cameralist.cgi and setcamera.cgi disclose credentials.... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-40379
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. rstp://.../medias2 does not require authorization.... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-40378
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killps.cgi deletes all data from the device.... Read more
- Published: Sep. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-40377
SmarterTools SmarterMail 16.x before build 7866 has stored XSS. The application fails to sanitize email content, thus allowing one to inject HTML and/or JavaScript into a page that will then be processed and stored by the application.... Read more
Affected Products : smartermail- Published: Sep. 08, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-40376
otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces over a .NET named pipe. A remote attack may be possible as well, by leveraging WsHTTPBinding for HTTP traffic on TCP port 9000.... Read more
Affected Products : update_manager- Published: Mar. 10, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-40375
Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still ret... Read more
Affected Products : openeyes- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024