Latest CVE Feed
-
7.2
HIGHCVE-2021-22720
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project.... Read more
Affected Products : c-bus_toolkit- EPSS Score: %12.00
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22719
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.... Read more
Affected Products : c-bus_toolkit- EPSS Score: %15.63
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22718
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files.... Read more
Affected Products : c-bus_toolkit- EPSS Score: %3.76
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-22717
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files.... Read more
Affected Products : c-bus_toolkit- EPSS Score: %17.68
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22716
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)... Read more
Affected Products : c-bus_toolkit- EPSS Score: %0.19
- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-22714
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.... Read more
- EPSS Score: %2.27
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22713
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause th... Read more
Affected Products : powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion8300_firmware powerlogic_ion8400_firmware powerlogic_ion8500_firmware powerlogic_ion7700_firmware powerlogic_ion7300_firmware powerlogic_ion7550_firmware +11 more products- EPSS Score: %0.92
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22712
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.13
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22711
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.13
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22710
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (C... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.70
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22709
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution w... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.70
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-22708
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1... Read more
Affected Products : evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_ev.2_firmware evlink_smart_wallbox_evb1a_firmware evlink_city_evc1s22p4 evlink_city_evc1s7p4 evlink_parking_evw2 evlink_parking_evf2 +2 more products- EPSS Score: %0.24
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-22707
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prio... Read more
Affected Products : evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_ev.2_firmware evlink_smart_wallbox_evb1a_firmware evlink_city_evc1s22p4 evlink_city_evc1s7p4 evlink_parking_evw2 evlink_parking_evf2 +2 more products- EPSS Score: %90.00
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-22706
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0... Read more
Affected Products : evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_ev.2_firmware evlink_smart_wallbox_evb1a_firmware evlink_city_evc1s22p4 evlink_city_evc1s7p4 evlink_parking_evw2 evlink_parking_evf2 +2 more products- EPSS Score: %0.28
- Published: Jul. 21, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22705
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure... Read more
- EPSS Score: %0.06
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-22704
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine E... Read more
- EPSS Score: %0.60
- Published: Sep. 02, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22703
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user crede... Read more
Affected Products : powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion9000_firmware powerlogic_pm8000_firmware powerlogic_ion8300_firmware powerlogic_ion8400_firmware powerlogic_ion8500_firmware +10 more products- EPSS Score: %0.16
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-22702
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure... Read more
Affected Products : powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion9000_firmware powerlogic_pm8000_firmware powerlogic_ion8300_firmware powerlogic_ion8400_firmware powerlogic_ion8500_firmware +14 more products- EPSS Score: %0.14
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
4.5
MEDIUMCVE-2021-22701
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the... Read more
Affected Products : powerlogic_ion7400_firmware powerlogic_ion7650_firmware powerlogic_ion8600_firmware powerlogic_ion8650_firmware powerlogic_ion8800_firmware powerlogic_ion9000_firmware powerlogic_pm8000_firmware powerlogic_ion8300_firmware powerlogic_ion8400_firmware powerlogic_ion8500_firmware +11 more products- EPSS Score: %0.15
- Published: Feb. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-22699
Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that could cause denial of service when specific crafted requests are sent to the controller over HTTP.... Read more
- EPSS Score: %0.55
- Published: May. 26, 2021
- Modified: Nov. 21, 2024