Latest CVE Feed
-
7.8
HIGHCVE-2021-32948
An out-of-bounds write issue exists in the DWG file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer and... Read more
- EPSS Score: %0.16
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32947
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.... Read more
Affected Products : fvdesigner- EPSS Score: %0.36
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32946
An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of the user-supplied data. This may result in several of out-of-bou... Read more
- EPSS Score: %0.30
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32945
An attacker could decipher the encryption and gain access to MDT AutoSave versions prior to v6.02.06.... Read more
- EPSS Score: %0.05
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32944
A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a memory corruption or arbitrary code execution, allo... Read more
- EPSS Score: %0.22
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32943
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1).... Read more
Affected Products : webaccess\/scada- EPSS Score: %0.86
- Published: Aug. 10, 2021
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2021-32942
The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowViewer) if an authorized, privileged user creates a diagnostic memory dump of the process and saves it to a non-protected location.... Read more
- EPSS Score: %0.04
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-32941
Annke N48PBB (Network Video Recorder) products of version 3.4.106 build 200422 and prior are vulnerable to a stack-based buffer overflow, which allows an unauthorized remote attacker to execute arbitrary code with the same privileges as the server user (r... Read more
- EPSS Score: %1.55
- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-32940
An out-of-bounds read issue exists in the DWG file-recovering procedure in the Drawings SDK (All versions prior to 2022.5) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer an... Read more
- EPSS Score: %0.32
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32939
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a project file that may permit arbitrary code execution.... Read more
Affected Products : fvdesigner- EPSS Score: %0.20
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-32938
Drawings SDK (All versions prior to 2022.4) are vulnerable to an out-of-bounds read due to parsing of DWG files resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows at... Read more
- EPSS Score: %0.21
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32937
An attacker can gain knowledge of a session temporary working folder where the getfile and putfile commands are used in MDT AutoSave versions prior to v6.02.06. An attacker can leverage this knowledge to provide a malicious command to the working director... Read more
- EPSS Score: %0.19
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32936
An out-of-bounds write issue exists in the DXF file-recovering procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer ... Read more
- EPSS Score: %0.17
- Published: Jun. 17, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-32935
The affected Cognex product, the In-Sight OPC Server versions v5.7.4 (96) and prior, deserializes untrusted data, which could allow a remote attacker access to system level permission commands and local privilege escalation.... Read more
Affected Products : in-sight_opc_server- EPSS Score: %0.32
- Published: May. 23, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-32934
The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not using AuthKey for IOTC conneciton, firmware using AVAPI module without enabling DTLS mechanism, and firmware using P2PTunnel or RDT mo... Read more
Affected Products : kalay_p2p_software_development_kit- EPSS Score: %0.10
- Published: May. 19, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-32933
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious proce... Read more
- EPSS Score: %0.22
- Published: Apr. 01, 2022
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-32932
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).... Read more
Affected Products : iview- EPSS Score: %0.19
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-32931
An uninitialized pointer in FATEK Automation FvDesigner, Versions 1.5.88 and prior may be exploited while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.... Read more
Affected Products : fvdesigner- EPSS Score: %0.30
- Published: Aug. 11, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-32930
The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change configurations and execute arbitrary code on the iView (versions prior to v5.7.03.6182).... Read more
Affected Products : iview- EPSS Score: %0.45
- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-32929
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.... Read more
Affected Products : gps_tracker- EPSS Score: %0.08
- Published: Apr. 22, 2022
- Modified: Nov. 21, 2024