|
199171
|
6.8 |
MEDIUM
Adjacent
|
elecom
|
wrh-733gbk_firmware wrh-733gwh_firmware
|
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS command…
|
CWE-78
OS Command
|
CVE-2021-20853
|
2024-11-21 14:47 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199172
|
6.8 |
MEDIUM
Adjacent
|
elecom
|
wrh-733gbk_firmware wrh-733gwh_firmware
|
Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privileg…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-20852
|
2024-11-21 14:47 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199173
|
8.8 |
HIGH
Network
|
browser_and_operating_system_finder_project
|
browser_and_operating_system_finder
|
Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator …
|
CWE-352
Origin Validation Error
|
CVE-2021-20851
|
2024-11-21 14:47 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199174
|
6.1 |
MEDIUM
Network
|
nttdocomo
|
wi-fi_station_sh-52a_firmware
|
Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthentic…
|
CWE-79
Cross-site Scripting
|
CVE-2021-20847
|
2024-11-21 14:47 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199175
|
9.8 |
CRITICAL
Network
|
alfasado
|
powercms
|
PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) allows a remote attacker to execute an arbitrary OS c…
|
CWE-78
OS Command
|
CVE-2021-20850
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199176
|
6.1 |
MEDIUM
Network
|
rwtxt_project
|
rwtxt
|
Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2021-20848
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199177
|
8.8 |
HIGH
Network
|
delitestudio
|
push_notifications_for_wordpress
|
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduc…
|
CWE-352
Origin Validation Error
|
CVE-2021-20846
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199178
|
8.8 |
HIGH
Network
|
xml-sitemaps
|
unlimited_sitemap_generator
|
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary o…
|
CWE-352
Origin Validation Error
|
CVE-2021-20845
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199179
|
5.7 |
MEDIUM
Network
|
yamaha ntt-west
|
rtx830_firmware nvr510_firmware nvr700w_firmware rtx1210_firmware biz_box_rtx830_firmware biz_box_nvr510_firmware biz_box_nvr700w_firmware biz_box_rtx1210_firmware
|
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2021-20844
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199180
|
5.4 |
MEDIUM
Network
|
yamaha ntt-west
|
rtx830_firmware nvr510_firmware nvr700w_firmware rtx1210_firmware biz_box_rtx830_firmware biz_box_nvr510_firmware biz_box_nvr700w_firmware biz_box_rtx1210_firmware
|
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier al…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2021-20843
|
2024-11-21 14:47 |
2021-11-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|