|
195121
|
4.3 |
MEDIUM
Network
|
retty
|
retty
|
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lea…
|
CWE-862
Missing Authorization
|
CVE-2021-20747
|
2024-11-21 14:47 |
2021-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195122
|
8.8 |
HIGH
Network
|
wp-currency
|
wordpress_currency_switcher
|
Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2021-20780
|
2024-11-21 14:47 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195123
|
8.8 |
HIGH
Network
|
codemiq
|
wordpress_email_template_designer
|
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via …
|
CWE-352
Origin Validation Error
|
CVE-2021-20779
|
2024-11-21 14:47 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195124
|
4.3 |
MEDIUM
Network
|
gu-global
|
gu
|
Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2 allows a remote attacker to lead a user to access an arbitrary website via the…
|
CWE-862
Missing Authorization
|
CVE-2021-20777
|
2024-11-21 14:47 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195125
|
9.8 |
CRITICAL
Network
|
a-stage-inc
|
at-40cm01sr_firmware sct-40cm01sr_firmware
|
Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.
|
CWE-287
Improper Authentication
|
CVE-2021-20776
|
2024-11-21 14:47 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195126
|
6.5 |
MEDIUM
Adjacent
|
elecom
|
wrc-1167fs-w_firmware wrc-1167fs-b_firmware wrc-1167fsa_firmware
|
WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2021-20738
|
2024-11-21 14:47 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195127
|
8.8 |
HIGH
Adjacent
|
elecom
|
wrc-300febk_firmware wrc-f300nf_firmware wrc-733febk_firmware wrh-300rd_firmware wrh-300bk_firmware wrh-300sv_firmware wrh-300wh_firmware wrh-h300wh_firmware wrh-h300bk_firmwa…
|
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker…
|
CWE-78
OS Command
|
CVE-2021-20739
|
2024-11-21 14:47 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195128
|
7.5 |
HIGH
Network
|
ec-cube
|
ec-cube
|
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2021-20778
|
2024-11-21 14:47 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195129
|
6.1 |
MEDIUM
Network
|
ikalka_rss_reader_project
|
ikalka_rss_reader
|
Cross-site scripting vulnerability in IkaIka RSS Reader all versions allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20752
|
2024-11-21 14:47 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195130
|
8.8 |
HIGH
Network
|
adobe
|
illustrator
|
Adobe Illustrator version 25.2 (and earlier) is affected by a Path Traversal vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achi…
|
-
|
CVE-2021-21102
|
2024-11-21 14:47 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|