|
197371
|
6.1 |
MEDIUM
Network
|
ec-cube
|
email_newsletters_management
|
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by le…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20743
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197372
|
6.1 |
MEDIUM
Network
|
ec-cube
|
business_form_output
|
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20742
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197373
|
6.1 |
MEDIUM
Network
|
hitachi
|
application_server_v10_manual
|
Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) ve…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20741
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197374
|
6.5 |
MEDIUM
Network
|
weseek
|
growi
|
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2021-20737
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197375
|
9.1 |
CRITICAL
Network
|
weseek
|
growi
|
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.
|
CWE-74
Injection
|
CVE-2021-20736
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197376
|
6.1 |
MEDIUM
Network
|
ec-cube
|
delivery_slip_number_mail delivery_slip_number_csv_bulk_registration delivery_slip_number
|
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earl…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20735
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197377
|
6.1 |
MEDIUM
Network
|
collne
|
welcart
|
Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbitrary script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20734
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197378
|
6.1 |
MEDIUM
Network
|
asken
|
asken
|
Improper authorization in handler for custom URL scheme vulnerability in ????????? (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbit…
|
CWE-862
Missing Authorization
|
CVE-2021-20733
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197379
|
9.8 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. A buffer overflow vulnerability exists in Contiki-NG versions prior to 4.6. After establishing a TCP sock…
|
-
|
CVE-2021-21281
|
2024-11-21 14:47 |
2021-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197380
|
9.8 |
CRITICAL
Network
|
contiki-ng
|
contiki-ng
|
Contiki-NG is an open-source, cross-platform operating system for internet of things devices. It is possible to cause an out-of-bounds write in versions of Contiki-NG prior to 4.6 when transmitting a…
|
-
|
CVE-2021-21280
|
2024-11-21 14:47 |
2021-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|