|
197031
|
7.5 |
HIGH
Network
|
phoenixcontact
|
fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_…
|
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will …
|
-
|
CVE-2021-21005
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197032
|
6.1 |
MEDIUM
Network
|
phoenixcontact
|
fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_…
|
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21004
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197033
|
5.3 |
MEDIUM
Network
|
phoenixcontact
|
fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_…
|
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the d…
|
-
|
CVE-2021-21003
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197034
|
6.1 |
MEDIUM
Network
|
ec-cube
|
business_form_output
|
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an ad…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20744
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197035
|
6.1 |
MEDIUM
Network
|
ec-cube
|
email_newsletters_management
|
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by le…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20743
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197036
|
6.1 |
MEDIUM
Network
|
ec-cube
|
business_form_output
|
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20742
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197037
|
6.1 |
MEDIUM
Network
|
hitachi
|
application_server_v10_manual
|
Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) ve…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20741
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197038
|
6.5 |
MEDIUM
Network
|
weseek
|
growi
|
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2021-20737
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197039
|
9.1 |
CRITICAL
Network
|
weseek
|
growi
|
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
|
CWE-74
Injection
|
CVE-2021-20736
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197040
|
6.1 |
MEDIUM
Network
|
ec-cube
|
delivery_slip_number_mail delivery_slip_number_csv_bulk_registration delivery_slip_number
|
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earl…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20735
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|