Latest CVE Feed
-
9.1
CRITICALCVE-2021-21016
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command injection via the WebAPI. Successful exploitation could lead to remote code execution by an authenticated attacker. Access to the admin conso... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2021-21015
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command injection via the customer attribute save controller. Successful exploitation could lead to arbitrary code execution by an authenticated a... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-21014
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful exploitation could lead to arbitrary code execution by an authenticated attacker. Access to the admin conso... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-21013
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the customer API module. Successful exploitation could lead to sensitive information disclosure and up... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21012
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direct object vulnerability (IDOR) in the checkout module. Successful exploitation could lead to sensitive information disclosure.... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-21011
Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. An attacker with permissions to write to the file system could leverage this vulnerability to e... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-21010
InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victi... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21009
Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier), 19.2.3 (and earlier) and 19.1.7 (and earlier) are affected by a server-side request forgery (SSRF) vulnerability. Successful exploitat... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-21008
Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2021-21007
Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21006
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of this issue requires user interactio... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-21005
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.... Read more
Affected Products : fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_firmware fl_switch_smcs_4tx-pn_firmware fl_switch_smcs_8tx_firmware +20 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-21004
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.... Read more
Affected Products : fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_firmware fl_switch_smcs_4tx-pn_firmware fl_switch_smcs_8tx_firmware +20 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21003
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.... Read more
Affected Products : fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_firmware fl_switch_smcs_4tx-pn_firmware fl_switch_smcs_8tx_firmware +20 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21002
In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.... Read more
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20999
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the ope... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-20998
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20997
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20996
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20995
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024