Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2021-27561
Known exploited
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
CVSS Score
9.8
EPSS Score
0.829
Published
2021-10-15
CVE-2021-20123
Known exploited
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVSS Score
7.5
EPSS Score
0.902
Published
2021-10-13
CVE-2021-20124
Known exploited
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.
CVSS Score
7.5
EPSS Score
0.963
Published
2021-10-13
CVE-2021-41357
Known exploited
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.021
Published
2021-10-13
CVE-2021-40449
Known exploited
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.741
Published
2021-10-13
CVE-2021-40450
Known exploited
Win32k Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.021
Published
2021-10-13
CVE-2021-37973
Known exploited
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVSS Score
9.6
EPSS Score
0.116
Published
2021-10-08
CVE-2021-37975
Known exploited
Use after free in V8 in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.349
Published
2021-10-08
CVE-2021-37976
Known exploited
Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVSS Score
6.5
EPSS Score
0.197
Published
2021-10-08
CVE-2021-30632
Known exploited
Out of bounds write in V8 in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.632
Published
2021-10-08


Contact Us

Shodan ® - All rights reserved