Latest CVE Feed
-
7.5
HIGHCVE-2021-20865
Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing authorization vulnerability in browsing database which may allow a user to browse unauthorized data via unspecified vectors.... Read more
Affected Products : advanced_custom_fields- Published: Dec. 13, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20864
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior,... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-20863
OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WR... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20862
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior,... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20861
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and pr... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20860
Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2021-20859
ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior,... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20858
Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20857
Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20856
Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20855
Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20854
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20853
ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2021-20852
Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute an arbitrary OS command via unspecified vec... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20851
Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.... Read more
Affected Products : browser_and_operating_system_finder- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-20850
PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 Series (End-of-Life, EOL) allows a remote attacker to execute an arbitrary OS command via unspecified vectors.... Read more
Affected Products : powercms- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20848
Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : rwtxt- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20847
Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of... Read more
- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20846
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web pag... Read more
Affected Products : push_notifications_for_wordpress- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20845
Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacker to hijack the authentication of an administrator and conduct arbitrary operation via a specially crafted web page.... Read more
Affected Products : unlimited_sitemap_generator- Published: Nov. 24, 2021
- Modified: Nov. 21, 2024