Latest CVE Feed
-
10.0
CRITICALCVE-2021-33841
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.... Read more
- EPSS Score: %1.48
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33840
The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.... Read more
Affected Products : luca- EPSS Score: %0.48
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33839
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.... Read more
Affected Products : luca- EPSS Score: %2.09
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33838
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.... Read more
Affected Products : luca- EPSS Score: %2.13
- Published: Jun. 04, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-33834
An issue was discovered in iscflashx64.sys 3.9.3.0 in Insyde H2OFFT 6.20.00. When handling IOCTL 0x22229a, the input used to allocate a buffer and copy memory is mishandled. This could cause memory corruption or a system crash.... Read more
- EPSS Score: %0.07
- Published: Sep. 08, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33833
ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).... Read more
- EPSS Score: %0.16
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-33831
api/account/register in the TH Wildau COVID-19 Contact Tracing application through 2021-09-01 has Incorrect Access Control. An attacker can interfere with tracing of infection chains by creating 500 random users within 2500 seconds.... Read more
Affected Products : covid-19_contact_tracing- EPSS Score: %8.03
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-33829
A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!> is mishandled.... Read more
- EPSS Score: %0.70
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-33828
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.... Read more
Affected Products : files_antivirus- EPSS Score: %0.54
- Published: Jan. 15, 2022
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-33827
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.... Read more
Affected Products : files_antivirus- EPSS Score: %2.88
- Published: Jan. 15, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33824
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then ... Read more
- EPSS Score: %0.64
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33823
An issue was discovered on MOXA Mgate MB3180 Version 2.1 Build 18113012. Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.... Read more
- EPSS Score: %0.54
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33822
An issue was discovered on 4GEE ROUTER HH70VB Version HH70_E1_02.00_22. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted. Then t... Read more
- EPSS Score: %0.56
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33820
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67.Attacker could send a huge amount of TCP SYN packet to make web service's resource exhausted. Then the web server is denial-of-service.... Read more
- EPSS Score: %0.56
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33818
An issue was discovered in UniFi Protect G3 FLEX Camera Version UVC.v4.30.0.67. Attackers can use slowhttptest tool to send incomplete HTTP request, which could make server keep waiting for the packet to finish the connection, until its resource exhausted... Read more
- EPSS Score: %0.56
- Published: Jun. 18, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33816
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %2.57
- Published: Nov. 10, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-33815
dwa_uncompress in libavcodec/exr.c in FFmpeg 4.4 allows an out-of-bounds array access because dc_count is not strictly checked.... Read more
Affected Products : ffmpeg- EPSS Score: %0.12
- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33813
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.... Read more
- EPSS Score: %0.06
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-33807
Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.... Read more
Affected Products : gespage- EPSS Score: %75.89
- Published: Jul. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-33806
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.... Read more
Affected Products : bdlib- EPSS Score: %6.86
- Published: Jun. 03, 2021
- Modified: Nov. 21, 2024