|
191101
|
9.8 |
CRITICAL
Network
|
qnap
|
ej1600_firmware tl-r1620sdc_firmware tl-r1620sep-rp_firmware tl-r1220sep-rp_firmware tl-d1600s_firmware tl-d800s_firmware tl-d400s_firmware tl-r1200s-rp_firmware tl-r400s_firm…
|
A stack buffer overflow vulnerability has been reported to affect QNAP device running NVR Storage Expansion. If exploited, this vulnerability allows attackers to execute arbitrary code. We have alrea…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-34345
|
2024-11-21 15:10 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191102
|
9.8 |
CRITICAL
Network
|
qnap
|
qusbcam2
|
A stack buffer overflow vulnerability has been reported to affect QNAP device running QUSBCam2. If exploited, this vulnerability allows attackers to execute arbitrary code. We have already fixed this…
|
CWE-787
Out-of-bounds Write
|
CVE-2021-34344
|
2024-11-21 15:10 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191103
|
9.8 |
CRITICAL
Network
|
eclipse
|
theia
|
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to Le…
|
CWE-22 CWE-611
Path Traversal XXE
|
CVE-2021-34436
|
2024-11-21 15:10 |
2021-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191104
|
8.8 |
HIGH
Network
|
eclipse
|
theia
|
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to …
|
CWE-346
Origin Validation Error
|
CVE-2021-34435
|
2024-11-21 15:10 |
2021-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191105
|
7.5 |
HIGH
Network
|
wago
|
750-880\/040-000_firmware 750-880\/025-002_firmware 750-880\/025-001_firmware 750-880\/025-000_firmware 750-831\/000-002_firmware 750-889_firmware 750-881_firmware 750-831_firmwa…
|
Missing Release of Resource after Effective Lifetime vulnerability in OpenSSL implementation of WAGO 750-831/xxx-xxx, 750-880/xxx-xxx, 750-881, 750-889 in versions FW4 up to FW15 allows an unauthenti…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2021-34581
|
2024-11-21 15:10 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191106
|
8.1 |
HIGH
Network
|
wago
|
750-890\/040-000_firmware 750-890\/025-001_firmware 750-890\/025-002_firmware 750-890\/025-000_firmware 750-832\/000-002_firmware 750-362_firmware 750-823_firmware 750-832_firmwa…
|
This vulnerability allows an attacker who has access to the WBM to read and write settings-parameters of the device by sending specifically constructed requests without authentication on multiple WAG…
|
-
|
CVE-2021-34578
|
2024-11-21 15:10 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191107
|
9.8 |
CRITICAL
Network
|
pepperl-fuchs
|
wha-gw-f2d2-0-as-z2-eth_firmware wha-gw-f2d2-0-as-z2-eth.eip_firmware
|
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.7 to 3.0.9 the SSH and telnet services are active with hard-coded credentials.
|
-
|
CVE-2021-34565
|
2024-11-21 15:10 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191108
|
5.5 |
MEDIUM
Local
|
pepperl-fuchs
|
wha-gw-f2d2-0-as-z2-eth_firmware wha-gw-f2d2-0-as-_z2-eth.eip_firmware
|
Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's credentials to the PEPPERL+FUCHS WirelessHART-Gateway 3.0.9.
|
-
|
CVE-2021-34564
|
2024-11-21 15:10 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191109
|
3.3 |
LOW
Local
|
pepperl-fuchs
|
wha-gw-f2d2-0-as-z2-eth_firmware wha-gw-f2d2-0-as-z2-eth.eip_firmware
|
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 and 3.0.9 the HttpOnly attribute is not set on a cookie. This allows the cookie's value to be read or set by client-side JavaScript.
|
-
|
CVE-2021-34563
|
2024-11-21 15:10 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191110
|
6.1 |
MEDIUM
Network
|
pepperl-fuchs
|
wha-gw-f2d2-0-as-z2-eth_firmware wha-gw-f2d2-0-as-z2-eth.eip_firmware
|
In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's response.
|
-
|
CVE-2021-34562
|
2024-11-21 15:10 |
2021-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|