Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown
CVE-2021-21953
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the process_msg() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted man-in-the-middle attack can lead to increased privileges.
0
Attacker Value
Unknown
CVE-2021-21952
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the CMD_DEVICE_GET_RSA_KEY_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to increased privileges.
0
Attacker Value
Unknown
CVE-2021-39312
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.
0
Attacker Value
Unknown
CVE-2021-21955
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
An authentication bypass vulnerability exists in the get_aes_key_info_by_packetid() function of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. Generic network sniffing can lead to password recovery. An attacker can sniff network traffic to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-21954
Disclosure Date: December 09, 2021 (last updated February 23, 2025)
A command execution vulnerability exists in the wifi_country_code_update functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to arbitrary command execution.
0
Attacker Value
Unknown
CVE-2021-21951
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function read_udp_push_config_file. A specially-crafted network packet can lead to code execution.
0
Attacker Value
Unknown
CVE-2021-21950
Disclosure Date: December 08, 2021 (last updated February 23, 2025)
An out-of-bounds write vulnerability exists in the CMD_DEVICE_GET_SERVER_LIST_REQUEST functionality of the home_security binary of Anker Eufy Homebase 2 2.1.6.9h in function recv_server_device_response_msg_process. A specially-crafted network packet can lead to code execution.
0
Attacker Value
Unknown
CVE-2021-21941
Disclosure Date: October 12, 2021 (last updated February 23, 2025)
A use-after-free vulnerability exists in the pushMuxer CreatePushThread functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted set of network packets can lead to remote code execution.
0
Attacker Value
Unknown
CVE-2021-21940
Disclosure Date: October 12, 2021 (last updated February 23, 2025)
A heap-based buffer overflow vulnerability exists in the pushMuxer processRtspInfo functionality of Anker Eufy Homebase 2 2.1.6.9h. A specially-crafted network packet can lead to a heap buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-20688
Disclosure Date: April 07, 2021 (last updated February 22, 2025)
Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via unspecified vectors.
0