Latest CVE Feed
-
5.4
MEDIUMCVE-2021-20749
Cross-site scripting vulnerability in Fudousan plugin ver5.7.0 and earlier, Fudousan Plugin Pro Single-User Type ver5.7.0 and earlier, and Fudousan Plugin Pro Multi-User Type ver5.7.0 and earlier allows a remote authenticated attacker to inject an arbitra... Read more
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-20748
Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 uses a hard-coded API key for an external service. By exploiting this vulnerability, API key for an external service may be obtained by analyzing data in the ap... Read more
Affected Products : retty- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20747
Improper authorization in handler for custom URL scheme vulnerability in Retty App for Android versions prior to 4.8.13 and Retty App for iOS versions prior to 4.11.14 allows a remote attacker to lead a user to access an arbitrary website via the vulnerab... Read more
Affected Products : retty- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2021-20746
Cross-site scripting vulnerability in WordPress Popular Posts 5.3.2 and earlier allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.... Read more
Affected Products : wordpress_popular_posts- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-20745
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.... Read more
Affected Products : inkdrop- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20744
Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script by leading an administrator or a user to a specially crafted page and to... Read more
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20743
Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.4 allows a remote attacker to inject an arbitrary script by leading a user to a specially crafted page and to perform ... Read more
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20742
Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to version 1.0.1 allows a remote attacker to inject an arbitrary script via unspecified vector.... Read more
- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20741
Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) version 10-11-01 and earlier and Hitachi Application Server V10 Manual (UNIX) version 10-11-01 and earlier) allows a remote attacker to ... Read more
Affected Products : application_server_v10_manual- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-20740
Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to FOS 6.4.3-08(NEC3.4.2) allow remot... Read more
- Published: Jun. 28, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20739
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitrary OS command via unspecified vect... Read more
- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20738
WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.... Read more
Affected Products : wrc-1167fs-w_firmware wrc-1167fs-b_firmware wrc-1167fsa_firmware wrc-1167fs-w wrc-1167fs-b wrc-1167fsa- Published: Jul. 07, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-20737
Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthorized pages without access privileges via unspecified vectors.... Read more
Affected Products : growi- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-20736
NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the information stored in the database via unspecified vectors.... Read more
Affected Products : growi- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20735
Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier, Delivery slip number csv bulk registration plugin (3.0 series) 1.0.8 and earlier, and Delivery slip number mail plugin (3.0 series) 1... Read more
Affected Products : delivery_slip_number delivery_slip_number_csv_bulk_registration delivery_slip_number_mail- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20733
Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions from v.3.0.0 to v.4.2.x allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.... Read more
Affected Products : asken- Published: Jun. 22, 2021
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2021-20732
The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on encrypted communication vi... Read more
Affected Products : smart_life- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-20731
WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands with root privileges via unspecified vectors.... Read more
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2021-20730
Improper access control vulnerability in WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allows an attacker to obtain configuration information via unspecified vectors.... Read more
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-20729
Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.... Read more
- Published: Mar. 31, 2022
- Modified: Nov. 21, 2024