Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2021-03-15 CVE-2021-25674 NULL Pointer Dereference vulnerability in Siemens Simatic S7-Plcsim 5.4
A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions).
local
low complexity
siemens CWE-476
2.1
2021-03-15 CVE-2021-25673 Infinite Loop vulnerability in Siemens Simatic S7-Plcsim
A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions).
local
low complexity
siemens CWE-835
4.9
2021-03-15 CVE-2021-25672 Unspecified vulnerability in Mendix Forgot Password 3.1.0/3.2.0
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1).
network
low complexity
mendix
6.5
2021-03-15 CVE-2021-25667 Stack-based Buffer Overflow vulnerability in Siemens products
A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2).
low complexity
siemens CWE-121
8.8
2021-03-15 CVE-2021-23357 Path Traversal vulnerability in TYK
All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOrUpdateApi function.
local
low complexity
tyk CWE-22
4.6
2021-03-15 CVE-2021-23356 Command Injection vulnerability in Kill-Process-By-Name Project Kill-Process-By-Name
This affects all versions of package kill-process-by-name.
network
low complexity
kill-process-by-name-project CWE-77
7.5
2021-03-15 CVE-2021-23355 Command Injection vulnerability in Ps-Kill Project Ps-Kill
This affects all versions of package ps-kill.
network
low complexity
ps-kill-project CWE-77
7.5
2021-03-15 CVE-2020-28387 XXE vulnerability in Siemens Solid Edge Se2021
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3).
network
siemens CWE-611
4.3
2021-03-15 CVE-2020-28385 Out-of-bounds Write vulnerability in Siemens Solid Edge Se2020/Se2021
A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP4).
network
siemens CWE-787
6.8
2021-03-15 CVE-2020-25241 Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Siemens products
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6).
network
low complexity
siemens CWE-1285
5.0