CVE Vulnerability Database

Search and browse 124 known security vulnerabilities. Filter by severity, vendor, product, and year.

124 vulnerabilities found
CVE-2021-45450
7.5 high

In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

Trustedfirmware Mbed Tls Dec 21, 2021
CVE-2021-43875
7.8 high

Microsoft Office Graphics Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-43256
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Dec 15, 2021
CVE-2021-4104
7.5 high

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote

Apache Log4J Dec 14, 2021
CVE-2021-44149
7.8 high

An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operat

Trustedfirmware Op-Tee Dec 7, 2021
CVE-2021-36133
7.1 high

The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.

Trustedfirmware Op-Tee Dec 7, 2021
CVE-2021-4019
7.8 high

vim is vulnerable to Heap-based Buffer Overflow

Neovim Neovim Dec 1, 2021
CVE-2021-42296
7.8 high

Microsoft Word Remote Code Execution Vulnerability

Microsoft 365 Apps Nov 10, 2021
CVE-2021-22792
7.5 high

A CWE-476: NULL Pointer Dereference vulnerability that could cause a Denial of Service on the Modicon PLC controller / simulator when updating the controller application with a specially crafted project file exists in Modicon M580 CPU (part numbers BMEP* and BMEH*, all versions), Modicon M340 CPU (p

Schneider-Electric Modicon M340 Bmxp341000 Sep 2, 2021
CVE-2021-22926
7.5 high

libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certif

Haxx Curl Aug 5, 2021
CVE-2021-33012
8.6 high

Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a denial-of-service condition. If successfully exploited, this vulnerability will ca

Rockwellautomation Micrologix 1100 Firmware Jul 9, 2021
CVE-2021-22766
7.5 high

A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet

Schneider-Electric Powerlogic Egx100 Firmware Jun 11, 2021
CVE-2021-32926
7.5 high

When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash. The user would no longer be able to authenticate to the controller (Micro800: All

Rockwellautomation Micro800 Firmware Jun 3, 2021
CVE-2021-32032
7.5 high

In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak.

Trustedfirmware Trusted Firmware-M May 21, 2021
CVE-2021-27386
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Wincc Runtime Advanced May 12, 2021
CVE-2021-27385
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Wincc Runtime Advanced May 12, 2021
CVE-2021-27383
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Wincc Runtime Advanced May 12, 2021
CVE-2021-25662
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Wincc Runtime Advanced May 12, 2021
CVE-2021-25661
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Wincc Runtime Advanced May 12, 2021
CVE-2021-25660
7.5 high

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl.

Siemens Simatic Hmi Comfort Outdoor Panels 7\" Firmware May 12, 2021
CVE-2021-29241
7.5 high

CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).

Codesys Control For Beaglebone Sl May 3, 2021
CVE-2021-22659
8.6 high

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a den

Rockwellautomation Micrologix 1400 Firmware Mar 25, 2021
CVE-2021-25667
8.8 high

A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC

Siemens Ruggedcom Rm1224 Firmware Mar 15, 2021
CVE-2021-22713
7.5 high

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.

Schneider-Electric Powerlogic Ion8650 Firmware Mar 11, 2021