Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2021-35394
Known exploited
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command injection vulnerability that can be exploited by remote unauthenticated attackers.
CVSS Score
9.8
EPSS Score
0.999
Published
2021-08-16
CVE-2021-35395
Known exploited
Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be used to configure the access point. Two versions of this management interface exists: one based on Go-Ahead named webs and another based on Boa named boa. Both of them are affected by these vulnerabilities. Specifically, these binaries are vulnerable to the following issues: - stack buffer overflow in formRebootCheck due to unsafe copy of submit-url parameter - stack buffer overflow in formWsc due to unsafe copy of submit-url parameter - stack buffer overflow in formWlanMultipleAP due to unsafe copy of submit-url parameter - stack buffer overflow in formWlSiteSurvey due to unsafe copy of ifname parameter - stack buffer overflow in formStaticDHCP due to unsafe copy of hostname parameter - stack buffer overflow in formWsc due to unsafe copy of 'peerPin' parameter - arbitrary command execution in formSysCmd via the sysCmd parameter - arbitrary command injection in formWsc via the 'peerPin' parameter Exploitability of identified issues will differ based on what the end vendor/manufacturer did with the Realtek SDK webserver. Some vendors use it as-is, others add their own authentication implementation, some kept all the features from the server, some remove some of them, some inserted their own set of features. However, given that Realtek SDK implementation is full of insecure calls and that developers tends to re-use those examples in their custom code, any binary based on Realtek SDK webserver will probably contains its own set of issues on top of the Realtek ones (if kept). Successful exploitation of these issues allows remote attackers to gain arbitrary code execution on the device.
CVSS Score
9.8
EPSS Score
0.98
Published
2021-08-16
CVE-2021-26086
Known exploited
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.
CVSS Score
5.3
EPSS Score
1.0
Published
2021-08-16
CVE-2021-36380
Known exploited
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
CVSS Score
9.8
EPSS Score
0.976
Published
2021-08-13
CVE-2021-36942
Known exploited
Windows LSA Spoofing Vulnerability
CVSS Score
7.5
EPSS Score
0.66
Published
2021-08-12
CVE-2021-36948
Known exploited
Windows Update Medic Service Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.267
Published
2021-08-12
CVE-2021-34484
Known exploited
Windows User Profile Service Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.217
Published
2021-08-12
CVE-2021-34486
Known exploited
Windows Event Tracing Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.093
Published
2021-08-12
CVE-2021-20028
Known exploited
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, specifically the SRA appliances running all 8.x firmware and 9.0.0.9-26sv or earlier
CVSS Score
9.8
EPSS Score
0.299
Published
2021-08-04
CVE-2021-30563
Known exploited
Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.089
Published
2021-08-03


Contact Us

Shodan ® - All rights reserved