|
196231
|
5.4 |
MEDIUM
Network
|
wordpress_popular_posts_project
|
wordpress_popular_posts
|
Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20746
|
2024-11-21 14:47 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196232
|
7.8 |
HIGH
Local
|
inkdrop
|
inkdrop
|
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.
|
CWE-78
OS Command
|
CVE-2021-20745
|
2024-11-21 14:47 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196233
|
8.8 |
HIGH
Network
|
hitachi nec
|
virtual_file_platform nas_gateway_nh4a_firmware nas_gateway_nh8a_firmware nas_gateway_nh4b_firmware nas_gateway_nh8b_firmware nas_gateway_nh4c_firmware nas_gateway_nh8c_firmware
|
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/N…
|
CWE-78
OS Command
|
CVE-2021-20740
|
2024-11-21 14:47 |
2021-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196234
|
7.5 |
HIGH
Network
|
phoenixcontact
|
fl_comserver_uni_232\/422\/485_firmware fl_comserver_uni_232\/422\/485-t_firmware
|
In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.
|
-
|
CVE-2021-21002
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196235
|
7.5 |
HIGH
Network
|
phoenixcontact
|
fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_…
|
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will …
|
-
|
CVE-2021-21005
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196236
|
6.1 |
MEDIUM
Network
|
phoenixcontact
|
fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_…
|
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.
|
CWE-79
Cross-site Scripting
|
CVE-2021-21004
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196237
|
5.3 |
MEDIUM
Network
|
phoenixcontact
|
fl_switch_smcs_16tx_firmware fl_switch_smcs_14tx\/2fx_firmware fl_switch_smcs_14tx\/2fx-sm_firmware fl_switch_smcs_8gt_firmware fl_switch_smcs_6gt\/2sfp_firmware fl_switch_smcs_8tx-pn_…
|
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the d…
|
-
|
CVE-2021-21003
|
2024-11-21 14:47 |
2021-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196238
|
6.1 |
MEDIUM
Network
|
ec-cube
|
business_form_output
|
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an ad…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20744
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196239
|
6.1 |
MEDIUM
Network
|
ec-cube
|
email_newsletters_management
|
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by le…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20743
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196240
|
6.1 |
MEDIUM
Network
|
ec-cube
|
business_form_output
|
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20742
|
2024-11-21 14:47 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|