Latest CVE Feed
-
9.8
CRITICALCVE-2021-21984
VMware vRealize Business for Cloud 7.x prior to 7.6.0 contains a remote code execution vulnerability due to an unauthorised end point. A malicious actor with network access may exploit this issue causing unauthorised remote code execution on vRealize Busi... Read more
Affected Products : vrealize_business_for_cloud- EPSS Score: %1.81
- Published: May. 07, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-21983
Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underly... Read more
- EPSS Score: %83.18
- Published: Mar. 31, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21982
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a val... Read more
- EPSS Score: %0.26
- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21980
The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to gain access to sensitive information.... Read more
- EPSS Score: %20.19
- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21979
In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/l... Read more
Affected Products : containers- EPSS Score: %0.17
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21978
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network ... Read more
Affected Products : view_planner- EPSS Score: %92.81
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21976
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execut... Read more
Affected Products : vsphere_replication- EPSS Score: %1.60
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21974
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may ... Read more
- EPSS Score: %69.53
- Published: Feb. 24, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-21971
An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigg... Read more
- EPSS Score: %0.43
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21970
An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [3] the json_object_get_string to populate the p_name global varia... Read more
- EPSS Score: %0.44
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21969
An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [4] the json_object_get_string to populate the p_payload global va... Read more
- EPSS Score: %0.44
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2021-21968
A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger ... Read more
- EPSS Score: %0.42
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-21967
An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigg... Read more
- EPSS Score: %0.28
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21966
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP reques... Read more
Affected Products : simplelink_cc32xx_software_development_kit cc3100_firmware cc3200_firmware cc3120 cc3130 cc3135 cc3220r cc3220s cc3220sf cc3230s +5 more products- EPSS Score: %2.02
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-21965
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigge... Read more
- EPSS Score: %0.44
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21964
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this ... Read more
- EPSS Score: %0.39
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-21963
An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man... Read more
- EPSS Score: %0.12
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-21962
A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-i... Read more
- EPSS Score: %1.90
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-21961
A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this v... Read more
- EPSS Score: %1.88
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-21960
A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger ... Read more
- EPSS Score: %1.88
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024