Search Results (119122 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-20673 1 Weseek 1 Growi 2024-11-21 4.8 Medium
Stored cross-site scripting vulnerability in Admin Page of GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote authenticated attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20672 1 Weseek 1 Growi 2024-11-21 6.1 Medium
Reflected cross-site scripting vulnerability due to insufficient verification of URL query parameters in GROWI (v4.2 Series) versions from v4.2.0 to v4.2.7 allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20671 1 Weseek 1 Growi 2024-11-21 7.2 High
Invalid file validation on the upload feature in GROWI versions v4.2.2 allows a remote attacker with administrative privilege to overwrite the files on the server, which may lead to arbitrary code execution.
CVE-2021-20670 1 Weseek 1 Growi 2024-11-21 7.5 High
Improper access control vulnerability in GROWI versions v4.2.2 and earlier allows a remote unauthenticated attacker to read the user's personal information and/or server's internal information via unspecified vectors.
CVE-2021-20667 1 Weseek 1 Growi 2024-11-21 5.4 Medium
Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI versions v4.2.2 and earlier allows remote authenticated attackers to inject an arbitrary script via a specially crafted content.
CVE-2021-20665 1 Movabletype 4 Movable Type, Movable Type Advanced, Movable Type Premium and 1 more 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20664 1 Movabletype 4 Movable Type, Movable Type Advanced, Movable Type Premium and 1 more 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20663 1 Movabletype 4 Movable Type, Movable Type Advanced, Movable Type Premium and 1 more 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Type 7 Series), Movable Type Advanced 7 r.4705 and earlier (Movable Type Advanced 7 Series), Movable Type 6.7.5 and earlier (Movable Type 6.7 Series), Movable Type Premium 1.39 and earlier, and Movable Type Premium Advanced 1.39 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.
CVE-2021-20655 1 Soliton 1 Filezen 2024-11-21 7.2 High
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
CVE-2021-20653 1 Nec 8 Csdj-a, Csdj-a Firmware, Csdj-b and 5 more 2024-11-21 5.3 Medium
Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 and earlier) allows remote attackers to bypass access restriction and to obtain unauthorized historical data without access privileges via unspecified vectors.
CVE-2021-20652 1 Name Directory Project 1 Name Directory 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2021-20651 1 Elecom 1 File Manager 2024-11-21 9.1 Critical
Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors.
CVE-2021-20650 1 Elecom 2 Ncc-ewf100rmwh2, Ncc-ewf100rmwh2 Firmware 2024-11-21 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.
CVE-2021-20647 1 Elecom 2 Wrc-300febk-s, Wrc-300febk-s Firmware 2024-11-21 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.
CVE-2021-20646 1 Elecom 2 Wrc-300febk-a, Wrc-300febk-a Firmware 2024-11-21 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.
CVE-2021-20645 1 Elecom 2 Wrc-300febk-a, Wrc-300febk-a Firmware 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.
CVE-2021-20643 1 Elecom 2 Ld-ps\/u1, Ld-ps\/u1 Firmware 2024-11-21 7.5 High
Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected device by processing a specially crafted request.
CVE-2021-20642 1 Logitech 2 Lan-w300n\/rs, Lan-w300n\/rs Firmware 2024-11-21 6.5 Medium
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.
CVE-2021-20641 1 Logitech 2 Lan-w300n\/rs, Lan-w300n\/rs Firmware 2024-11-21 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device settings may be conducted.
CVE-2021-20637 1 Logitech 2 Lan-w300n\/pr5b, Lan-w300n\/pr5b Firmware 2024-11-21 6.5 Medium
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.