CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
UliCMS before 2020.2 has PageController stored XSS.
UliCMS before 2020.2 has XSS during PackageController uninstall.
Weak encryption in the Quick Pairing mode in the eWeLink mobile application (Android application V4.9.2 and earlier, iOS application V4.9.1 and earlier) allows physically proximate attackers to eavesdrop on Wi-Fi credentials and other sensitive information by monitoring the Wi-Fi spectrum during the pairing process.
The direct_mail extension through 5.2.3 for TYPO3 allows Information Disclosure via a newsletter subscriber data Special Query.
An elevation of privilege vulnerability exists in the way that the wlansvc.dll handles objects in memory, aka 'Windows WLAN Service Elevation of Privilege Vulnerability'.
The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via jumpUrl.
The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber tables.
The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log entries.
The iframe plugin before 4.5 for WordPress does not sanitize a URL.
1288h_v5, 1288h_v5_firmware, 2288h_v5, 2288h_v5_firmware, 2488_v5, 2488_v5_firmware, 5300hi, 5300hi_firmware, 5310ei, 5310ei_firmware
2021-04-23
N/A
7.5 HIGH
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
