Latest CVE Feed
-
7.8
HIGHCVE-2021-34202
There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640) 1.01B04. Ordinary permissions can be elevated to administrator permissions, resulting in local arbitrary code execution. An attacker can combine other vulnerabil... Read more
- EPSS Score: %0.25
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-34201
D-Link DIR-2640-US 1.01B04 is vulnerable to Buffer Overflow. There are multiple out-of-bounds vulnerabilities in some processes of D-Link AC2600(DIR-2640). Local ordinary users can overwrite the global variables in the .bss section, causing the process cr... Read more
- EPSS Score: %0.06
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-34193
Stack overflow vulnerability in OpenSC smart card middleware before 0.23 via crafted responses to APDUs.... Read more
Affected Products : opensc- EPSS Score: %0.41
- Published: Aug. 22, 2023
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-34190
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "Name" or "Prefix" fields under the "Create New Rat... Read more
Affected Products : pbx- EPSS Score: %0.24
- Published: Jul. 06, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34187
main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 parameter.... Read more
- EPSS Score: %84.79
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2021-34174
A vulnerability exists in Broadcom BCM4352 and BCM43684 chips. Any wireless router using BCM4352 and BCM43684 will be affected, such as ASUS AX6100. An attacker may cause a Denial of Service (DoS) to any device connected to BCM4352 or BCM43684 routers via... Read more
- EPSS Score: %0.15
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-34173
An attacker can cause a Denial of Service and kernel panic in v4.2 and earlier versions of Espressif esp32 via a malformed beacon csa frame. The device requires a reboot to recover.... Read more
- EPSS Score: %0.30
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34170
Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.... Read more
Affected Products : dark_souls_iii- EPSS Score: %3.18
- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34166
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.... Read more
Affected Products : simple_food_website- EPSS Score: %0.66
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-34165
A SQL Injection vulnerability in Sourcecodester Basic Shopping Cart 1.0 allows a remote attacker to Bypass Authentication and become Admin.... Read more
Affected Products : basic_shopping_cart- EPSS Score: %0.66
- Published: Jul. 30, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34150
The Bluetooth Classic implementation on Bluetrum AB5301A devices with unknown firmware versions does not properly handle the reception of oversized DM1 LMP packets while no other BT connections are active, allowing attackers in radio range to prevent new ... Read more
- EPSS Score: %0.13
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34149
The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it ... Read more
- EPSS Score: %0.15
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34148
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with a greater ACL Length after completion of the LMP setup procedure, allowing attackers in rad... Read more
- EPSS Score: %0.10
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34147
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 does not properly handle the reception of a malformed LMP timing accuracy response followed by multiple reconnections to the link slave, allowing attackers to ... Read more
- EPSS Score: %0.10
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34146
The Bluetooth Classic implementation in the Cypress CYW920735Q60EVB does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service and restart (crash) of the device by flood... Read more
- EPSS Score: %0.10
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-34145
The Bluetooth Classic implementation in the Cypress WICED BT stack through 2.9.0 for CYW20735B1 devices does not properly handle the reception of LMP_max_slot with an invalid Baseband packet type (and LT_ADDRESS and LT_ADDR) after completion of the LMP se... Read more
- EPSS Score: %0.12
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34144
The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C BT SDK through 0.9.1 does not properly handle the reception of truncated LMP_SCO_Link_Request packets while no other BT connections are active, allowing attackers in radio range to prevent n... Read more
- EPSS Score: %0.14
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-34143
The Bluetooth Classic implementation in the Zhuhai Jieli AC6366C_DEMO_V1.0 does not properly handle the reception of continuous unsolicited LMP responses, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by floodin... Read more
- EPSS Score: %0.24
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-34141
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harm... Read more
- EPSS Score: %0.06
- Published: Dec. 17, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-34129
LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via directory traversal in the uploadImg, ol... Read more
Affected Products : laiketui- EPSS Score: %0.87
- Published: Jun. 15, 2021
- Modified: Nov. 21, 2024