|
191001
|
7.5 |
HIGH
Network
|
wago
|
750-8100_firmware 750-8101_firmware 750-8101\/025-000_firmware 750-8102_firmware 750-8102\/025-000_firmware 750-8202_firmware 750-8202\/000-011_firmware 750-8202\/000-012_firmwar…
|
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service.
|
-
|
CVE-2021-34568
|
2024-11-21 15:10 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191002
|
9.1 |
CRITICAL
Network
|
wago
|
750-8100_firmware 750-8101_firmware 750-8101\/025-000_firmware 750-8102_firmware 750-8102\/025-000_firmware 750-8202_firmware 750-8202\/000-011_firmware 750-8202\/000-012_firmwar…
|
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in…
|
-
|
CVE-2021-34566
|
2024-11-21 15:10 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191003
|
9.8 |
CRITICAL
Network
|
netgear
|
r8000_firmware
|
Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.c…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-34236
|
2024-11-21 15:10 |
2022-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191004
|
7.5 |
HIGH
Network
|
apache
|
hive
|
Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2021-34538
|
2024-11-21 15:10 |
2022-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191005
|
8.8 |
HIGH
Network
|
qnap
|
nas_proxy_server
|
A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, this vulnerability allows remote attackers to inject malicious code. We h…
|
CWE-352
Origin Validation Error
|
CVE-2021-34360
|
2024-11-21 15:10 |
2022-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191006
|
7.3 |
HIGH
Local
|
xinje
|
xd\/e_series_plc_program_tool
|
A vulnerability exists in XINJE XD/E Series PLC Program Tool in versions up to v3.5.1 that can allow an authenticated, local attacker to load a malicious DLL. Local access is required to successfully…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-34606
|
2024-11-21 15:10 |
2022-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191007
|
7.3 |
HIGH
Local
|
xinje
|
xd\/e_series_plc_program_tool
|
A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vul…
|
-
|
CVE-2021-34605
|
2024-11-21 15:10 |
2022-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191008
|
8.8 |
HIGH
Network
|
bender
|
cc612_firmware icc15xx_firmware
|
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed …
|
-
|
CVE-2021-34602
|
2024-11-21 15:10 |
2022-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191009
|
9.8 |
CRITICAL
Network
|
bender
|
cc612_firmware icc15xx_firmware
|
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacke…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2021-34601
|
2024-11-21 15:10 |
2022-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191010
|
8.8 |
HIGH
Network
|
bender
|
cc612_firmware icc15xx_firmware
|
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.
|
-
|
CVE-2021-34592
|
2024-11-21 15:10 |
2022-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|