Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-09 | CVE-2021-20145 | Improper Authentication vulnerability in Gryphonconnect Gryphon Tower Firmware Gryphon Tower routers contain an unprotected openvpn configuration file which can grant attackers access to the Gryphon homebound VPN network which exposes the LAN interfaces of other users' devices connected to the same service. | 7.5 |
2021-12-09 | CVE-2021-21955 | Improper Authentication vulnerability in Anker Eufy Homebase 2 Firmware 2.1.6.9H An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. | 7.5 |
2021-12-09 | CVE-2021-40279 | SQL Injection vulnerability in Zzcms An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/bad.php. | 7.2 |
2021-12-09 | CVE-2021-40280 | SQL Injection vulnerability in Zzcms An SQL Injection vulnerablitly exits in zzcms 8.2, 8.3, 2020, and 2021 via the id parameter in admin/dl_sendmail.php. | 7.2 |
2021-12-09 | CVE-2021-41246 | Unspecified vulnerability in Auth0 Express Openid Connect Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. | 8.8 |
2021-12-09 | CVE-2021-41449 | Path Traversal vulnerability in Netgear Rax35 Firmware, Rax38 Firmware and Rax40 Firmware A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet. | 7.1 |
2021-12-09 | CVE-2021-43065 | Incorrect Permission Assignment for Critical Resource vulnerability in Fortinet Fortinac A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows attacker to gain higher privileges via the access to sensitive system data. | 7.8 |
2021-12-09 | CVE-2021-43068 | Improper Authentication vulnerability in Fortinet Fortiauthenticator 6.4.0 A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login portal. | 8.1 |
2021-12-09 | CVE-2021-43071 | Out-of-bounds Write vulnerability in Fortinet Fortiweb A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to the LogReport API controller. | 8.8 |
2021-12-09 | CVE-2021-36194 | Out-of-bounds Write vulnerability in Fortinet Fortiweb Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests. | 8.8 |