Latest CVE Feed
-
5.3
MEDIUMCVE-2021-20993
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20992
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20991
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20990
In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recov... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-20989
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device in... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-20988
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.... Read more
Affected Products : rcx_rtos ice1-16di-g60l-v1d_firmware ice1-16dio-g60l-c1-v1d_firmware ice1-16dio-g60l-v1d_firmware ice1-8di8do-g60l-c1-v1d_firmware ice1-8di8do-g60l-v1d_firmware ice1-8iol-g30l-v1d_firmware ice1-8iol-g60l-v1d_firmware ice1-8iol-s2-g60l-v1d_firmware ice1-16di-g60l-v1d +7 more products- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-20987
A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.... Read more
Affected Products : wcs_firmware ethernet\/ip_adapter_firmware pxv100-f200-b25-v1d_firmware pxv100i-f200-b25-v1d_firmware pcv100-f200-b25-v1d-6011-6720_firmware pcv50-f200-b25-v1d_firmware pcv80-f200-b25-v1d_firmware pcv100-f200-b25-v1d-6011_firmware ethernet\/ip_adapter wcs3b-ls510 +13 more products- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20986
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.... Read more
Affected Products : profinet_io_device_firmware pgv100-f200a-b17-v1d_firmware pgv150i-f200a-b17-v1d_firmware pgv100-f200-b17-v1d-7477_firmware pxv100-f200-b17-v1d_firmware pxv100-f200-b17-v1d-3636_firmware pcv80-f200-b17-v1d_firmware pcv100-f200-b17-v1d_firmware pcv50-f200-b17-v1d_firmware pcv100-f200-b17-v1d-6011-6997_firmware +63 more products- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2021-20877
Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, imageCLASS ... Read more
- Published: Feb. 08, 2022
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20876
Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an administrative privilege to obtain sensitive information store... Read more
Affected Products : groupsession- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20875
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites and cond... Read more
Affected Products : groupsession- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20874
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated attacker to access... Read more
Affected Products : groupsession- Published: Dec. 24, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20873
Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are developed with Yappli versions since v7.3.6 and prior to v9.30.0, they are vulnerable to improper authorizat... Read more
Affected Products : yappli- Published: Dec. 28, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20872
Protection mechanism failure vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 36... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20871
Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2021-20870
Improper handling of exceptional conditions vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and ear... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20869
Exposure of sensitive information to an unauthorized actor vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
4.5
MEDIUMCVE-2021-20868
Incorrect authorization vulnerability in KONICA MINOLTA bizhub series (bizhub C750i G00-35 and earlier, bizhub C650i/C550i/C450i G00-B6 and earlier, bizhub C360i/C300i/C250i G00-B6 and earlier, bizhub 750i/650i/550i/450i G00-37 and earlier, bizhub 360i/30... Read more
- Published: Jan. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20867
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to move the unauthorized field group via unspecified vectors... Read more
Affected Products : advanced_custom_fields- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20866
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to obtain the unauthorized information via unspecified vect... Read more
Affected Products : advanced_custom_fields- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024