|
195171
|
6.1 |
MEDIUM
Network
|
calendar01_project
|
calendar01
|
Reflected cross-site scripting vulnerability in the admin page of [Calendar01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20725
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195172
|
6.1 |
MEDIUM
Network
|
telop01_project
|
telop01
|
Reflected cross-site scripting vulnerability in the admin page of [Telop01] free edition ver1.0.1 and earlier allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20724
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195173
|
6.1 |
MEDIUM
Network
|
mailform01_project
|
mailform01
|
Reflected cross-site scripting vulnerability in [MailForm01] free edition (versions which the last updated date listed at the top of descriptions in the program file is from 2014 December 12 to 2018 …
|
CWE-79
Cross-site Scripting
|
CVE-2021-20723
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195174
|
7.8 |
HIGH
Local
|
fujitsu
|
scansnap_manager
|
Untrusted search path vulnerability in the installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2021-20722
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195175
|
7.8 |
HIGH
Local
|
qualitysoft
|
qnd
|
Privilege escalation vulnerability in QND Advance/Premium/Standard Ver.11.0.4i and earlier allows an attacker who can log in to the PC where the product's Windows client is installed to gain administ…
|
CWE-269
Improper Privilege Management
|
CVE-2021-20713
|
2024-11-21 14:47 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195176
|
9.8 |
CRITICAL
Network
|
kujirahand
|
konawiki
|
KonaWiki2 versions prior to 2.2.4 allows a remote attacker to upload arbitrary files via unspecified vectors. If the file contains PHP scripts, arbitrary code may be executed.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-20721
|
2024-11-21 14:47 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195177
|
9.8 |
CRITICAL
Network
|
kujirahand
|
konawiki
|
SQL injection vulnerability in the KonaWiki2 versions prior to 2.2.4 allows remote attackers to execute arbitrary SQL commands and to obtain/alter the information stored in the database via unspecifi…
|
CWE-89
SQL Injection
|
CVE-2021-20720
|
2024-11-21 14:47 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195178
|
6.8 |
MEDIUM
Adjacent
|
nippon-antenna
|
rfntps_firmware
|
RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via unspecified…
|
CWE-78
OS Command
|
CVE-2021-20719
|
2024-11-21 14:47 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195179
|
7.5 |
HIGH
Network
|
openidc fedoraproject oracle
|
mod_auth_openidc fedora essbase
|
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2021-20718
|
2024-11-21 14:47 |
2021-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195180
|
9.8 |
CRITICAL
Network
|
weidmueller
|
uc20-wl2000-ac_firmware uc20-wl2000-iot_firmware iot-gw30_firmware iot-gw30-4g-eu_firmware
|
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usage is accidentally accessible via external network interfaces. By exploiting thi…
|
NVD-CWE-Other
|
CVE-2021-20999
|
2024-11-21 14:47 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|