|
196861
|
6.1 |
MEDIUM
Network
|
zettlr
|
zettlr
|
Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by loading a file or code snippet containing an invalid iframe into Zettlr.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20727
|
2024-11-21 14:47 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196862
|
6.5 |
MEDIUM
Network
|
wago
|
750-823_firmware 750-829_firmware 750-831_firmware 750-832_firmware 750-852_firmware 750-862_firmware 750-880_firmware 750-881_firmware 750-882_firmware 750-885_firmware
|
On WAGO PFC200 devices in different firmware versions with special crafted packets an authorised attacker with network access to the device can access the file system with higher privileges.
|
CWE-22
Path Traversal
|
CVE-2021-21001
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196863
|
7.5 |
HIGH
Network
|
wago
|
750-823_firmware 750-829_firmware 750-831_firmware 750-832_firmware 750-852_firmware 750-862_firmware 750-880_firmware 750-881_firmware 750-882_firmware 750-885_firmware
|
On WAGO PFC200 devices in different firmware versions with special crafted packets an attacker with network access to the device could cause a denial of service for the login service of the runtime.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2021-21000
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196864
|
7.8 |
HIGH
Local
|
overwolf
|
overwolf
|
Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the ins…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20726
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196865
|
6.1 |
MEDIUM
Network
|
calendar01_project
|
calendar01
|
Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20725
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196866
|
6.1 |
MEDIUM
Network
|
telop01_project
|
telop01
|
Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20724
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196867
|
6.1 |
MEDIUM
Network
|
mailform01_project
|
mailform01
|
Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 …
|
CWE-79
Cross-site Scripting
|
CVE-2021-20723
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196868
|
7.8 |
HIGH
Local
|
fujitsu
|
scansnap_manager
|
Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20722
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196869
|
7.8 |
HIGH
Local
|
qualitysoft
|
qnd
|
Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the product's Windows client is installed to gain administ…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20713
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196870
|
9.8 |
CRITICAL
Network
|
kujirahand
|
konawiki
|
KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20721
|
2024-11-21 14:47 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|