Latest CVE Feed
-
9.1
CRITICALCVE-2021-20651
Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors.... Read more
Affected Products : file_manager- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20650
Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/o... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2021-20649
ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-20648
ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20647
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or ... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20646
Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or ... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20645
Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20644
ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20643
Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected device by processing a specially crafted request.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20642
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20641
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device sett... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-20640
Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-20639
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2021-20638
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20637
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20636
Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via a specially crafted URL. As a result, unintended operations to the device such as changes of the device se... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20635
Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover PIN and access the network.... Read more
- Published: Feb. 12, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20634
Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Custom App via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20633
Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the date of Cabinet via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20632
Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Bulletin Board via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024