Latest CVE Feed
-
7.0
HIGHCVE-2021-21007
Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-21006
Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially crafted font file. Successful exploitation could lead to arbitrary code execution. Exploitation of this issue requires user interactio... Read more
- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-21005
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.... Read more
Affected Products : fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_firmware fl_switch_smcs_4tx-pn_firmware fl_switch_smcs_8tx_firmware +20 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2021-21004
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.... Read more
Affected Products : fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_firmware fl_switch_smcs_4tx-pn_firmware fl_switch_smcs_8tx_firmware +20 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-21003
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.... Read more
Affected Products : fl_nat_smn_8tx-m_firmware fl_nat_smn_8tx_firmware fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_firmware fl_switch_smcs_4tx-pn_firmware fl_switch_smcs_8tx_firmware +20 more products- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-21002
In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.... Read more
- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20999
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting this vulnerability the device may be manipulated or the ope... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-20998
In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it is possible to create users.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20997
In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-based Management users.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20996
In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferred to third parties.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20995
In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user credentials.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20994
In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to inject possible malicious code into the Web-Based Management.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2021-20993
In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the index of the resources located inside the directory.... Read more
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-20992
In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP protocol. Communication between the user and the device can be eavesdropped to hijack sessions, tokens and passwords.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20991
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability.... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20990
In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessible on port 8000 and some API endpoints could be accessed without authentication to trigger a shutdown, a reboot or a reboot into recov... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-20989
Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud to provide remote access and remote support capabilities. This connection can be intercepted using DNS spoofing attack and a device in... Read more
- Published: Apr. 19, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-20988
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.... Read more
Affected Products : rcx_rtos ice1-16di-g60l-v1d_firmware ice1-16dio-g60l-c1-v1d_firmware ice1-16dio-g60l-v1d_firmware ice1-8di8do-g60l-c1-v1d_firmware ice1-8di8do-g60l-v1d_firmware ice1-8iol-g30l-v1d_firmware ice1-8iol-g60l-v1d_firmware ice1-8iol-s2-g60l-v1d_firmware ice1-16di-g60l-v1d +7 more products- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
8.6
HIGHCVE-2021-20987
A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.... Read more
Affected Products : wcs_firmware ethernet\/ip_adapter_firmware pxv100-f200-b25-v1d_firmware pxv100i-f200-b25-v1d_firmware pcv100-f200-b25-v1d-6011-6720_firmware pcv50-f200-b25-v1d_firmware pcv80-f200-b25-v1d_firmware pcv100-f200-b25-v1d-6011_firmware ethernet\/ip_adapter wcs3b-ls510 +13 more products- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20986
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.... Read more
Affected Products : profinet_io_device_firmware pgv100-f200a-b17-v1d_firmware pgv150i-f200a-b17-v1d_firmware pgv100-f200-b17-v1d-7477_firmware pxv100-f200-b17-v1d_firmware pxv100-f200-b17-v1d-3636_firmware pcv80-f200-b17-v1d_firmware pcv100-f200-b17-v1d_firmware pcv50-f200-b17-v1d_firmware pcv100-f200-b17-v1d-6011-6997_firmware +63 more products- Published: Feb. 16, 2021
- Modified: Nov. 21, 2024