LiveActive security incident?Get immediate response
CVE archive

January 2021

Browse CVE records published in January 2021, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 2235 matching CVEs · Page 7 of 45.

Medium · CVSS 6.5

CVE-2021-22570: Nullptr Dereference in Protobuf

Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.

Published Jan 26, 2022 · Updated Apr 21, 2025

High · CVSS 8.1

CVE-2021-44463: Emerson DeltaV Uncontrolled Search Path Element

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

Published Jan 28, 2022 · Updated Apr 17, 2025

High · CVSS 7.8

CVE-2021-23157: WECON LeviStudioU

WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.

Published Jan 14, 2022 · Updated Apr 16, 2025

High · CVSS 7.8

CVE-2021-23138: WECON LeviStudioU

WECON LeviStudioU Versions 2019-09-21 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code.

Published Jan 14, 2022 · Updated Apr 16, 2025

High · CVSS 7.3

CVE-2021-23233: Fresenius Kabi Agilia Connect Infusion System

Sensitive endpoints in Fresenius Kabi Agilia Link+ v3.0 and prior can be accessed without any authentication information such as the session cookie. An attacker can send requests to sensitive endpoints as an unauthenticated user to perform critical actions or modify critical configuration parameters.

Published Jan 21, 2022 · Updated Apr 16, 2025

Medium · CVSS 5.3

CVE-2021-23195: Fresenius Kabi Agilia Connect Infusion System exposure of information through directory listing

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 has the option for automated indexing (directory listing) activated. When accessing a directory, a web server delivers its entire content in HTML form. If an index file does not exist and directory listing is enabled, all content of the directory will be displayed, allowing an attacker to identify and access files on the server.

Published Jan 21, 2022 · Updated Apr 16, 2025

Medium · CVSS 6.5

CVE-2021-31562: Fresenius Kabi Agilia Connect Infusion System use of a broken or risky cryptographic algorithm

The SSL/TLS configuration of Fresenius Kabi Agilia Link + version 3.0 has serious deficiencies that may allow an attacker to compromise SSL/TLS sessions in different ways. An attacker may be able to eavesdrop on transferred data, manipulate data allegedly secured by SSL/TLS, and impersonate an entity to gain access to sensitive information.

Published Jan 21, 2022 · Updated Apr 16, 2025

Medium · CVSS 5.4

CVE-2021-33848: Fresenius Kabi Agilia Connect Infusion System cross site scripting

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 is vulnerable to reflected cross-site scripting attacks. An attacker could inject JavaScript in a GET parameter of HTTP requests and perform unauthorized actions such as stealing internal information and performing actions in context of an authenticated user.

Published Jan 21, 2022 · Updated Apr 16, 2025

High · CVSS 7.3

CVE-2021-43355: Fresenius Kabi Agilia Connect Infusion System use of client side authentication

Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.

Published Jan 21, 2022 · Updated Apr 16, 2025

High · CVSS 7.1

CVE-2021-40413: An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality o...

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The UpgradePrepare is the API that checks if a provided filename identifies a new version of the RLC-410W firmware. If the version is new, it would be possible, allegedly, to later on perform the Upgrade. An attacker can send an HTTP request to trigger this vulnerability.

Published Jan 28, 2022 · Updated Apr 15, 2025

High · CVSS 7.1

CVE-2021-40414: An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality o...

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. The SetMdAlarm API sets the movement detection parameters, giving the ability to set the sensitivity of the camera per a range of hours, and which of the camera spaces to ignore when considering movement detection. Because in cgi_check_ability the SetMdAlarm API does not have a specific case, the user permission will default to 7. This will give non-administrative users the possibility to change the movement detection parameters.

Published Jan 28, 2022 · Updated Apr 15, 2025

High · CVSS 7.1

CVE-2021-40415: An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality o...

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. In cgi_check_ability the Format API does not have a specific case, the user permission will default to 7. This will give non-administrative users the possibility to format the SD card and reboot the device.

Published Jan 28, 2022 · Updated Apr 15, 2025

High · CVSS 7.1

CVE-2021-40416: An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality o...

An incorrect default permission vulnerability exists in the cgiserver.cgi cgi_check_ability functionality of reolink RLC-410W v3.0.0.136_20121102. All the Get APIs that are not included in cgi_check_ability are already executable by any logged-in users. An attacker can send an HTTP request to trigger this vulnerability.

Published Jan 28, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.1

CVE-2021-40408: An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-41...

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->username variable, that has the value of the userName parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

Published Jan 28, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.1

CVE-2021-40409: An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-41...

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->password variable, that has the value of the password parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection.

Published Jan 28, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.1

CVE-2021-40410: An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-41...

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [4] the dns_data->dns1 variable, that has the value of the dns1 parameter provided through the SetLocal API, is not validated properly. This would lead to an OS command injection.

Published Jan 28, 2022 · Updated Apr 15, 2025

Critical · CVSS 9.1

CVE-2021-40411: An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-41...

An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [6] the dns_data->dns2 variable, that has the value of the dns2 parameter provided through the SetLocalLink API, is not validated properly. This would lead to an OS command injection.

Published Jan 28, 2022 · Updated Apr 15, 2025