• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2021-26731
Iac-ast2500a Firmware, Lannerinc
Iac-ast2500, Iac-ast2500a, Iac-ast2500a_firmware, Iac-ast2500_firmware
2023-02-03
N/A
9.8 CRITICAL
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
CVE-2021-26730
Iac-ast2500a Firmware, Lannerinc
Iac-ast2500, Iac-ast2500a, Iac-ast2500a_firmware, Iac-ast2500_firmware
2022-12-03
N/A
9.8 CRITICAL
A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
CVE-2021-26729
Iac-ast2500a Firmware, Lannerinc
Iac-ast2500, Iac-ast2500a, Iac-ast2500a_firmware, Iac-ast2500_firmware
2022-12-03
N/A
9.8 CRITICAL
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
CVE-2021-26728
Iac-ast2500a Firmware, Lannerinc
Iac-ast2500, Iac-ast2500a, Iac-ast2500a_firmware, Iac-ast2500_firmware
2022-12-03
N/A
9.8 CRITICAL
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
CVE-2021-26727
Iac-ast2500a Firmware, Lannerinc
Iac-ast2500, Iac-ast2500a, Iac-ast2500a_firmware, Iac-ast2500_firmware
2022-12-03
N/A
9.8 CRITICAL
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner Inc IAC-AST2500A standard firmware version 1.10.0.
CVE-2021-26726
2022-02-24
N/A
8.8 HIGH
A remote code execution vulnerability affecting a Valmet DNA service listening on TCP port 1517, allows an attacker to execute commands with SYSTEM privileges This issue affects: Valmet DNA versions from Collection 2012 until Collection 2021.
CVE-2021-26725
2021-02-26
N/A
4.9 MEDIUM
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
CVE-2021-26724
2021-02-26
N/A
7.2 HIGH
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
CVE-2021-26723
2021-03-04
N/A
6.1 MEDIUM
Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
CVE-2021-26722
2021-02-08
N/A
6.1 MEDIUM
LinkedIn Oncall through 1.4.0 allows reflected XSS via /query because of mishandling of the "No results found for" message in the search bar.
« Previous 1 … 8,155 8,156 8,157 8,158 8,159 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE