|
196311
|
5.5 |
MEDIUM
Local
|
mitsubishielectric
|
melsoft_navigator gx_works2 ezsocket
|
Integer Underflow vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5.…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2021-20607
|
2024-11-21 14:46 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196312
|
5.5 |
MEDIUM
Local
|
mitsubishielectric
|
melsoft_navigator gx_works2 ezsocket
|
Out-of-bounds Read vulnerability in Mitsubishi Electric GX Works2 versions 1.606G and prior, Mitsubishi Electric MELSOFT Navigator versions 2.84N and prior and Mitsubishi Electric EZSocket versions 5…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-20606
|
2024-11-21 14:46 |
2021-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196313
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed oplog entries, resulting in a potential denial of service on secondaries. This…
|
CWE-20
Improper Input Validation
|
CVE-2021-20330
|
2024-11-21 14:46 |
2021-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196314
|
7.5 |
HIGH
Network
|
ibm
|
db2
|
IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as under certain circumstances the LOAD utility does not enforce directory restricti…
|
NVD-CWE-noinfo
|
CVE-2021-20373
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196315
|
9.8 |
CRITICAL
Network
|
gryphonconnect
|
gryphon_tower_firmware
|
An unprotected ssh private key exists on the Gryphon devices which could be used to achieve root access to a server affiliated with Gryphon's development and infrastructure. At the time of discovery,…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20146
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196316
|
7.5 |
HIGH
Network
|
gryphonconnect
|
gryphon_tower_firmware
|
Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices …
|
CWE-287
Improper Authentication
|
CVE-2021-20145
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196317
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n…
|
CWE-78
OS Command
|
CVE-2021-20144
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196318
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n…
|
CWE-78
OS Command
|
CVE-2021-20143
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196319
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n…
|
CWE-78
OS Command
|
CVE-2021-20142
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196320
|
8.8 |
HIGH
Adjacent
|
gryphonconnect
|
gryphon_tower_firmware
|
An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same n…
|
CWE-78
OS Command
|
CVE-2021-20141
|
2024-11-21 14:46 |
2021-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|