Search Results (357012 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-33004 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
CVE-2021-33003 1 Deltaww 1 Diaenergie 2024-11-21 5.5 Medium
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a weak hashing algorithm.
CVE-2021-33002 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
CVE-2021-33000 1 Advantech 1 Webaccess\/hmi Designer 2024-11-21 7.8 High
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
CVE-2021-32999 1 Aveva 1 Suitelink 2024-11-21 7.5 High
Improper handling of exceptional conditions in SuiteLink server while processing command 0x01
CVE-2021-32995 1 Hornerautomation 1 Cscape 2024-11-21 7.8 High
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute code in the context of the current process.
CVE-2021-32993 1 Philips 4 Intellibridge Ec40, Intellibridge Ec40 Firmware, Intellibridge Ec80 and 1 more 2024-11-21 8.1 High
IntelliBridge EC 40 and 60 Hub (C.00.04 and prior) contains hard-coded credentials, such as a password or a cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.
CVE-2021-32992 1 Fatek 1 Winproladder 2024-11-21 9.8 Critical
FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory buffer, which may allow an attacker to execute arbitrary code.
CVE-2021-32991 1 Deltaww 1 Diaenergie 2024-11-21 4.3 Medium
Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an attacker to cause a user to carry out an action unintentionally.
CVE-2021-32990 1 Fatek 1 Winproladder 2024-11-21 9.8 Critical
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attacker to execute arbitrary code.
CVE-2021-32988 1 Fatek 1 Winproladder 2024-11-21 9.8 Critical
FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code.
CVE-2021-32987 1 Aveva 1 Suitelink 2024-11-21 7.5 High
Null pointer dereference in SuiteLink server while processing command 0x0b
CVE-2021-32983 1 Deltaww 1 Diaenergie 2024-11-21 9.8 Critical
A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter keyword before using it as part of an SQL query. A remote, unauthenticated attacker can exploit this issue to execute arbitrary code in the context of NT SERVICE\MSSQLSERVER.
CVE-2021-32979 1 Aveva 1 Suitelink 2024-11-21 7.5 High
Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a
CVE-2021-32975 1 Hornerautomation 1 Cscape 2024-11-21 7.8 High
Cscape (All Versions prior to 9.90 SP5) lacks proper validation of user-supplied data when parsing project files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute code in the context of the current process.
CVE-2021-32972 1 Panasonic 1 Fpwin Pro 2024-11-21 5.5 Medium
Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the user executing software.
CVE-2021-32971 1 Aveva 1 Suitelink 2024-11-21 7.5 High
Null pointer dereference in SuiteLink server while processing command 0x07
CVE-2021-32967 1 Deltaww 1 Diaenergie 2024-11-21 9.8 Critical
Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without being authenticated or authorized, which may allow the attacker to log in and use the device with administrative privileges.
CVE-2021-32963 1 Aveva 1 Suitelink 2024-11-21 7.5 High
Null pointer dereference in SuiteLink server while processing commands 0x03/0x10
CVE-2021-32959 1 Aveva 1 Suitelink 2024-11-21 8.1 High
Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06