Search Results (349374 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-20785 1 Groupsession 3 Groupsession, Groupsession Bycloud, Groupsession Zion 2024-11-21 4.8 Medium
Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, GroupSession byCloud from ver3.0.3 to the version prior to ver5.1.0, and GroupSession ZION from ver3.0.3 to the version prior to ver5.1.0) allows a remote attacker to inject an arbitrary script by sending a specially crafted request to a specific URL.
CVE-2021-20783 1 Softbank 2 Optical Bb Unit E-wmta, Optical Bb Unit E-wmta Firmware 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the authentication of administrators via a specially crafted page.
CVE-2021-20782 1 Tipsandtricks-hq 1 Software License Manager 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in Software License Manager versions prior to 4.4.6 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2021-20781 1 Pluginus 1 Wordpress Meta Data And Taxonomies Filter 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in WordPress Meta Data Filter & Taxonomies Filter versions prior to v.1.2.8 and versions prior to v.2.2.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2021-20780 1 Wp-currency 1 Wordpress Currency Switcher 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2021-20779 1 Codemiq 1 Wordpress Email Template Designer 2024-11-21 8.8 High
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2021-20778 1 Ec-cube 1 Ec-cube 2024-11-21 7.5 High
Improper access control vulnerability in EC-CUBE 4.0.6 (EC-CUBE 4 series) allows a remote attacker to bypass access restriction and obtain sensitive information via unspecified vectors.
CVE-2021-20777 1 Gu-global 1 Gu 2024-11-21 4.3 Medium
Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2 allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
CVE-2021-20776 1 A-stage-inc 4 At-40cm01sr, At-40cm01sr Firmware, Sct-40cm01sr and 1 more 2024-11-21 9.8 Critical
Improper authentication vulnerability in SCT-40CM01SR and AT-40CM01SR allows an attacker to bypass access restriction and execute an arbitrary command via telnet.
CVE-2021-20775 1 Cybozu 1 Garoon 2024-11-21 4.3 Medium
Improper input validation vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the data of Comment and Space without the viewing privilege.
CVE-2021-20774 1 Cybozu 1 Garoon 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in some functions of E-mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20773 1 Cybozu 1 Garoon 2024-11-21 4.3 Medium
There is a vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.5.0, which may allow a remote authenticated attacker to delete the route information Workflow without the appropriate privilege.
CVE-2021-20772 1 Cybozu 1 Garoon 2024-11-21 4.3 Medium
Information disclosure vulnerability in Bulletin of Cybozu Garoon 4.10.0 to 5.5.0 allows a remote authenticated attacker to obtain the title of Bulletin without the viewing privilege.
CVE-2021-20771 1 Cybozu 1 Garoon 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in some functions of E-Mail of Cybozu Garoon 4.0.0 to 5.5.0 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20770 1 Cybozu 1 Garoon 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20769 1 Cybozu 1 Garoon 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.6.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20768 1 Cybozu 1 Garoon 2024-11-21 4.3 Medium
Operational restrictions bypass vulnerability in Scheduler and MultiReport of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to delete the data of Scheduler and MultiReport without the appropriate privilege.
CVE-2021-20767 1 Cybozu 1 Garoon 2024-11-21 5.4 Medium
Cross-site scripting vulnerability in Full Text Search of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20766 1 Cybozu 1 Garoon 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in Message of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.
CVE-2021-20765 1 Cybozu 1 Garoon 2024-11-21 6.1 Medium
Cross-site scripting vulnerability in Bulletin of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote attacker to inject an arbitrary script via unspecified vectors.