| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| Microsoft SharePoint Server Spoofing Vulnerability |
| Windows Print Spooler Elevation of Privilege Vulnerability |
| Windows Bind Filter Driver Elevation of Privilege Vulnerability |
| Windows Port Class Library Elevation of Privilege Vulnerability |
| Win32k Elevation of Privilege Vulnerability |
| Windows Error Reporting Elevation of Privilege Vulnerability |
| Windows Print Spooler Elevation of Privilege Vulnerability |
| DirectX Elevation of Privilege Vulnerability |
| Remote Desktop Protocol Server Information Disclosure Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Elevation of Privilege Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Azure Sphere Unsigned Code Execution Vulnerability |
| Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2. |
| An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated network attacker, may expose Sensitive Information. |
| Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs. |
| On Crestron DM-NVX-DIR, DM-NVX-DIR80, and DM-NVX-ENT devices before the DM-XIO/1-0-3-802 patch, the password can be changed by sending an unauthenticated WebSocket request. |
| Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a race condition in which a file created under "%PROGRAMDATA%\Razer Chroma\SDK\Apps" can be replaced before it is executed by the server. The attacker must have access to port 54236 for a registration step. |