|
199701
|
9.8 |
CRITICAL
Network
|
alfasado
|
powercms
|
PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) allows a remote attacker to execute an arbitrary OS c…
|
CWE-78
OS Command
|
CVE-2021-20850
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199702
|
6.1 |
MEDIUM
Network
|
rwtxt_project
|
rwtxt
|
Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20848
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199703
|
8.8 |
HIGH
Network
|
delitestudio
|
push_notifications_for_wordpress
|
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduc…
|
CWE-352
Origin Validation Error
|
CVE-2021-20846
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199704
|
8.8 |
HIGH
Network
|
xml-sitemaps
|
unlimited_sitemap_generator
|
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary o…
|
CWE-352
Origin Validation Error
|
CVE-2021-20845
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199705
|
5.7 |
MEDIUM
Network
|
yamaha ntt-west
|
rtx830_firmware nvr510_firmware nvr700w_firmware rtx1210_firmware biz_box_rtx830_firmware biz_box_nvr510_firmware biz_box_nvr700w_firmware biz_box_rtx1210_firmware
|
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-20844
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199706
|
5.4 |
MEDIUM
Network
|
yamaha ntt-west
|
rtx830_firmware nvr510_firmware nvr700w_firmware rtx1210_firmware biz_box_rtx830_firmware biz_box_nvr510_firmware biz_box_nvr700w_firmware biz_box_rtx1210_firmware
|
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier al…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2021-20843
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199707
|
6.5 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Cross-site request forgery (CSRF) vulnerability in EC-CUBE 2 series 2.11.0 to 2.17.1 allows a remote attacker to hijack the authentication of Administrator and delete Administrator via a specially cr…
|
CWE-352
Origin Validation Error
|
CVE-2021-20842
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199708
|
6.5 |
MEDIUM
Network
|
ec-cube
|
ec-cube
|
Improper access control in Management screen of EC-CUBE 2 series 2.11.2 to 2.17.1 allows a remote authenticated attacker to bypass access restriction and to alter System settings via unspecified vect…
|
NVD-CWE-Other
|
CVE-2021-20841
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199709
|
6.1 |
MEDIUM
Network
|
saasproject
|
booking_package
|
Cross-site scripting vulnerability in Booking Package - Appointment Booking Calendar System versions prior to 1.5.11 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20840
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199710
|
7.5 |
HIGH
Network
|
mercari
|
mercari
|
Improper authorization in handler for custom URL scheme vulnerability in Android App 'Mercari (Merpay) - Marketplace and Mobile Payments App' (Japan version) versions prior to 4.49.1 allows a remote …
|
CWE-862
Missing Authorization
|
CVE-2021-20835
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|