Latest CVE Feed
-
7.5
HIGHCVE-2021-21979
In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r108 for Laravel 7 and 8.5.11-debian-10-r0 for Laravel 8, the file /tmp/app/.env is generated at the time that the docker image bitnami/l... Read more
Affected Products : containers- EPSS Score: %0.17
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-21978
VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network ... Read more
Affected Products : view_planner- EPSS Score: %92.81
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2021-21976
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 contain a post-authentication command injection vulnerability which may allow an authenticated admin user to perform a remote code execut... Read more
Affected Products : vsphere_replication- EPSS Score: %1.60
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21974
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may ... Read more
- EPSS Score: %69.53
- Published: Feb. 24, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-21971
An out-of-bounds write vulnerability exists in the URL_decode functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to an out-of-bounds write. An attacker can perform a man-in-the-middle attack to trigg... Read more
- EPSS Score: %0.43
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21970
An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [3] the json_object_get_string to populate the p_name global varia... Read more
- EPSS Score: %0.44
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21969
An out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. The HandleIncomingSeaCloudMessage function uses at [4] the json_object_get_string to populate the p_payload global va... Read more
- EPSS Score: %0.44
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2021-21968
A file write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to arbitrary file overwrite. An attacker can perform a man-in-the-middle attack to trigger ... Read more
- EPSS Score: %0.42
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2021-21967
An out-of-bounds write vulnerability exists in the OTA update task functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted MQTT payload can lead to denial of service. An attacker can perform a man-in-the-middle attack to trigg... Read more
- EPSS Score: %0.28
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21966
An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP reques... Read more
Affected Products : simplelink_cc32xx_software_development_kit cc3100_firmware cc3200_firmware cc3120 cc3130 cc3135 cc3220r cc3220s cc3220sf cc3230s +5 more products- EPSS Score: %2.02
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2021-21965
A denial of service vulnerability exists in the SeaMax remote configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigge... Read more
- EPSS Score: %0.44
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21964
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. Specially-crafted network packets can lead to denial of service. An attacker can send a malicious packet to trigger this ... Read more
- EPSS Score: %0.39
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-21963
An information disclosure vulnerability exists in the Web Server functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted man-in-the-middle attack can lead to a disclosure of sensitive information. An attacker can perform a man... Read more
- EPSS Score: %0.12
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2021-21962
A heap-based buffer overflow vulnerability exists in the OTA Update u-download functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A series of specially-crafted MQTT payloads can lead to remote code execution. An attacker must perform a man-i... Read more
- EPSS Score: %1.90
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-21961
A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this v... Read more
- EPSS Score: %1.88
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-21960
A stack-based buffer overflow vulnerability exists in both the LLMNR functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger ... Read more
- EPSS Score: %1.88
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21959
A misconfiguration exists in the MQTTS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. This misconfiguration significantly simplifies a man-in-the-middle attack, which directly leads to control of device functionality.... Read more
- EPSS Score: %0.31
- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-21958
A heap-based buffer overflow vulnerability exists in the Hword HwordApp.dll functionality of Hancom Office 2020 11.0.0.2353. A specially-crafted malformed file can lead to memory corruption and potential arbitrary code execution. An attacker can provide a... Read more
Affected Products : hancom_office_2020- EPSS Score: %0.83
- Published: Feb. 16, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-21957
A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2.16900.0. A specially-crafted command injection can lead to elevated capabilities. An attacker can provide a malicious file to trigger ... Read more
Affected Products : remote_connector- EPSS Score: %0.61
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-21956
A php unserialize vulnerability exists in the Ai-Bolit functionality of CloudLinux Inc Imunify360 5.10.2. A specially-crafted malformed file can lead to potential arbitrary command execution. An attacker can provide a malicious file to trigger this vulner... Read more
Affected Products : imunify360- EPSS Score: %0.41
- Published: Apr. 14, 2022
- Modified: Nov. 21, 2024