Vulnerability index

Browse CVEs

360 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-21928 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘mac_filter’ parameter to trigger thi… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21929 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘prod_filter’ parameter to trigger th… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21930 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at ‘sn_filter’ parameter to trigger this… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21931 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests at‘ stat_filter’ parameter to trigger th… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21932 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘name_filter’ paramet… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21933 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘esn_filter’ paramete… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21934 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this at ‘imei_filter’ paramet… R Seenet No fix yet Fix from $1,6002021-12-22 MEDIUM 6.5 CVE-2021-21935 A specially-crafted HTTP request can lead to SQL injection. An attacker can make authenticated HTTP requests to trigger this vulnerability at ‘host_a… R Seenet No fix yet Fix from $1,6002021-12-22 HIGH 7.8 CVE-2021-21910 A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021). A s… R Seenet No fix yet Fix from $1,9502021-12-22 MEDIUM 6.1 CVE-2021-42703 This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting … Webaccess Hmi Designer 2.1.11.0+ Fix from $1,6002021-11-15 HIGH 7.8 CVE-2021-42706 This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer Webaccess Hmi Designer 2.1.11.0+ Fix from $1,9502021-11-15 MEDIUM 5.3 CVE-2021-32951 WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources… Webaccess\/nms after 3.0.3 Fix from $1,6002021-10-27 CRITICAL 9.8 CVE-2021-33023 Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code. Webaccess after 9.0.2 Fix from $2,3002021-10-18 CRITICAL 9.8 CVE-2021-38389EPSS 10% Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. Webaccess after 9.0.2 Fix from $2,3002021-10-18 CRITICAL 9.8 CVE-2021-38408EPSS 12% A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of use… Webaccess after 9.02 Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-32943 The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/… Webaccess\/scada 8.4.5 / 9.0.1+ Fix from $2,3002021-08-10 MEDIUM 6.1 CVE-2021-22676 UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code.… Webaccess\/scada 8.4.5 / 9.0.1+ Fix from $1,6002021-08-10 MEDIUM 6.5 CVE-2021-22674 The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories o… Webaccess\/scada 8.4.5 / 9.0.1+ Fix from $1,6002021-08-10 CRITICAL 9.8 CVE-2021-21805EPSS 70% An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially crafted HT… R Seenet No fix yet Fix from $2,3002021-08-05 CRITICAL 9.8 CVE-2021-21804 A local file inclusion (LFI) vulnerability exists in the options.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). A specially cr… R Seenet No fix yet Fix from $2,3002021-07-16 MEDIUM 6.1 CVE-2021-21799EPSS 12% Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits … R Seenet No fix yet Fix from $1,6002021-07-16 MEDIUM 6.1 CVE-2021-21800EPSS 14% Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a s… R Seenet No fix yet Fix from $1,6002021-07-16 MEDIUM 6.1 CVE-2021-21801EPSS 63% This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by… R Seenet No fix yet Fix from $1,6002021-07-16 MEDIUM 6.1 CVE-2021-21802EPSS 10% This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by… R Seenet No fix yet Fix from $1,6002021-07-16 MEDIUM 6.1 CVE-2021-21803EPSS 8% This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by… R Seenet No fix yet Fix from $1,6002021-07-16 HIGH 7.8 CVE-2021-33000 Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. U… Webaccess\/hmi Designer after 2.1.9.95 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-33002 Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction … Webaccess\/hmi Designer after 2.1.9.95 Fix from $1,9502021-06-24 HIGH 7.8 CVE-2021-33004 The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacke… Webaccess\/hmi Designer after 2.1.9.95 Fix from $1,9502021-06-24 MEDIUM 6.5 CVE-2021-32954 Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary fil… Webaccess\/scada after 9.0.1 Fix from $1,6002021-06-18 MEDIUM 6.1 CVE-2021-32956 Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that c… Webaccess\/scada after 9.0.1 Fix from $1,6002021-06-18