Latest CVE Feed
-
6.5
MEDIUMCVE-2021-20631
Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to alter the data of Custom App via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20630
Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and obtain the data of Phone Messages via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20629
Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20628
Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors. Note that this vulnerability occurs only when using Mozilla Firefox.... Read more
- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20627
Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20626
Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to bypass access restriction and alter the data of Workflow via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20625
Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Bulletin Board via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20624
Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to bypass access restriction and alter the data of Scheduler via unspecified vectors.... Read more
Affected Products : office- Published: Mar. 18, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-20623
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.... Read more
Affected Products : video_insight_vms- Published: Feb. 05, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20622
Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.... Read more
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20621
Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20620
Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.... Read more
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20619
Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : growi- Published: Jan. 19, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-20618
Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remote attackers to bypass authentication and to gain an administrative privilege which may result in obtaining the sensitive information on... Read more
- Published: Jan. 14, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-20617
Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows remote attackers to execute an arbitrary OS command, or gain an administrative privilege which may result in obtaining the sensitive in... Read more
- Published: Jan. 14, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20616
Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : skysea_client_view- Published: Jan. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20613
Improper initialization vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.16 and prior, FX3U-ENET-L Firmware version 1.16 and prior and FX3U-ENET-P502 Firmware version 1.16 and prior allows a remote unauthenticated attacker to cause a denial-o... Read more
Affected Products : fx3u-enet-l_firmware fx3u-enet-p502_firmware fx3u-enet_firmware fx3u-enet fx3u-enet-l fx3u-enet-p502- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20612
Lack of administrator control over security vulnerability in MELSEC-F series FX3U-ENET Firmware version 1.14 and prior, FX3U-ENET-L Firmware version 1.14 and prior and FX3U-ENET-P502 Firmware version 1.14 and prior allows a remote unauthenticated attacker... Read more
Affected Products : fx3u-enet-l_firmware fx3u-enet-p502_firmware fx3u-enet_firmware fx3u-enet fx3u-enet-l fx3u-enet-p502- Published: Jan. 14, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20611
Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R Series R08/16/32/120PSFCPU... Read more
Affected Products : melsec_iq-r_r00_cpu_firmware melsec_iq-r_r01_cpu_firmware melsec_iq-r_r02_cpu_firmware melsec_iq-r_r04_cpu_firmware melsec_iq-r_r08_cpu_firmware melsec_iq-r_r120_cpu_firmware melsec_iq-r_r16_cpu_firmware melsec_iq-r_r32_cpu_firmware melsec_iq-r_r04_pcpu_firmware melsec_iq-r_r08_pcpu_firmware +100 more products- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-20610
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/08/16/32/120(EN)CPU, MELSEC iQ-R Series R08/16/32/120SFCPU, MELSEC iQ-R Series R08/16/32/120PCPU, MELSEC iQ-R ... Read more
Affected Products : melsec_iq-r_r00_cpu_firmware melsec_iq-r_r01_cpu_firmware melsec_iq-r_r02_cpu_firmware melsec_iq-r_r04_cpu_firmware melsec_iq-r_r08_cpu_firmware melsec_iq-r_r120_cpu_firmware melsec_iq-r_r16_cpu_firmware melsec_iq-r_r32_cpu_firmware melsec_iq-r_r04_pcpu_firmware melsec_iq-r_r08_pcpu_firmware +100 more products- Published: Dec. 01, 2021
- Modified: Nov. 21, 2024