Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-32932 Unspecified vulnerability in Advantech Iview
The affected product is vulnerable to a SQL injection, which may allow an unauthorized attacker to disclose information on the iView (versions prior to v5.7.03.6182).
network
low complexity
advantech
7.5
2021-06-11 CVE-2020-13663 Cross-Site Request Forgery (CSRF) vulnerability in Drupal
Cross Site Request Forgery vulnerability in Drupal Core Form API does not properly handle certain form input from cross-site requests, which can lead to other vulnerabilities.
network
low complexity
drupal CWE-352
8.8
2021-06-11 CVE-2021-20591 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R00/01/02CPU all versions, R04/08/16/32/120(EN)CPU all versions, R08/16/32/120SFCPU all versions, R08/16/32/120PCPU all versions, R08/16/32/120PSFCPU all versions) allows a remote unauthenticated attacker to prevent legitimate clients from connecting to the MELSOFT transmission port (TCP/IP) by not closing a connection properly, which may lead to a denial of service (DoS) condition.
network
low complexity
mitsubishielectric CWE-400
7.5
2021-06-11 CVE-2021-22750 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition.
local
low complexity
schneider-electric
7.8
2021-06-11 CVE-2021-22751 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.
local
low complexity
schneider-electric
7.8
2021-06-11 CVE-2021-22752 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.
local
low complexity
schneider-electric
7.8
2021-06-11 CVE-2021-22753 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.
local
low complexity
schneider-electric
7.8
2021-06-11 CVE-2021-22754 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.
local
low complexity
schneider-electric
7.8
2021-06-11 CVE-2021-22755 Unspecified vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data, when a malicious CGF file is imported to IGSS Definition.
local
low complexity
schneider-electric
7.8
2021-06-11 CVE-2021-22756 Out-of-bounds Read vulnerability in Schneider-Electric Interactive Graphical Scada System
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data validation, when a malicious CGF file is imported to IGSS Definition.
local
low complexity
schneider-electric CWE-125
7.8