|
200091
|
8.1 |
HIGH
Network
|
yappli
|
yappli
|
Yappli is an application development platform which provides the function to access a requested URL using Custom URL Scheme. When Android apps are developed with Yappli versions since v7.3.6 and prio…
|
CWE-862
Missing Authorization
|
CVE-2021-20873
|
2024-11-21 14:47 |
2021-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200092
|
6.8 |
MEDIUM
Network
|
groupsession
|
groupsession
|
Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows an attacker with an admini…
|
CWE-22
Path Traversal
|
CVE-2021-20876
|
2024-11-21 14:47 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200093
|
6.1 |
MEDIUM
Network
|
groupsession
|
groupsession
|
Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and earlier allows a remote unauthenticated at…
|
CWE-601
Open Redirect
|
CVE-2021-20875
|
2024-11-21 14:47 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200094
|
7.5 |
HIGH
Network
|
groupsession
|
groupsession
|
Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier, and GroupSession ZION ver5.1.1 and ea…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2021-20874
|
2024-11-21 14:47 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200095
|
7.5 |
HIGH
Network
|
idec
|
microsmart_fc6a_firmware microsmart_plus_fc6a_firmware data_file_manager windedit windldr
|
Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 a…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-20827
|
2024-11-21 14:47 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200096
|
7.6 |
HIGH
Adjacent
|
idec
|
microsmart_fc6a_firmware microsmart_plus_fc6a_firmware data_file_manager windedit windldr
|
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.1…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2021-20826
|
2024-11-21 14:47 |
2021-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200097
|
6.5 |
MEDIUM
Network
|
advancedcustomfields
|
advanced_custom_fields
|
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in moving the field group which may allow a user to m…
|
CWE-862
Missing Authorization
|
CVE-2021-20867
|
2024-11-21 14:47 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200098
|
6.5 |
MEDIUM
Network
|
advancedcustomfields
|
advanced_custom_fields
|
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in obtaining the user list which may allow a user to …
|
CWE-862
Missing Authorization
|
CVE-2021-20866
|
2024-11-21 14:47 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200099
|
7.5 |
HIGH
Network
|
advancedcustomfields
|
advanced_custom_fields
|
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse…
|
CWE-862
Missing Authorization
|
CVE-2021-20865
|
2024-11-21 14:47 |
2021-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200100
|
5.4 |
MEDIUM
Network
|
elecom
|
wrc-2533ghbk-i_firmware
|
Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20858
|
2024-11-21 14:47 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|