Show filters
93 Total Results
Displaying 1-10 of 93
Sort by:
Attacker Value
Unknown

CVE-2018-19957

Disclosure Date: September 10, 2021 (last updated February 23, 2025)
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS running QTS, QuTS hero, and QuTScloud. This vulnerability allows remote attackers to launch privacy and security attacks. We have already fixed this vulnerability in the following versions: QTS 4.5.4.1715 build 20210630 and later QuTS hero h4.5.4.1771 build 20210825 and later QuTScloud c4.5.6.1755 build 20210809 and later
Attacker Value
Unknown

CVE-2021-3734

Disclosure Date: August 26, 2021 (last updated February 23, 2025)
yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames
Attacker Value
Unknown

CVE-2021-3731

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable to 'clickjacking'. This allows an attacker to trick a targetted user to execute unintended actions.
Attacker Value
Unknown

CVE-2021-32070

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking attack due to an insecure header response. A successful exploit could allow an attacker to modify the browser header and redirect users.
Attacker Value
Unknown

CVE-2021-37788

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted HTTP packets with malicious iFrame data. A successful exploit could allow the attacker to perform a clickjacking attack where the user is tricked into clicking a malicious link.
Attacker Value
Unknown

CVE-2021-33596

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe that the content is served by a legit domain. Exploiting the vulnerability requires the user to click on a specially crafted, seemingly legitimate URL containing an embedded malicious redirect while using F-Secure Safe Browser for iOS.
Attacker Value
Unknown

CVE-2021-20560

Disclosure Date: July 23, 2021 (last updated February 23, 2025)
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 199229.
Attacker Value
Unknown

CVE-2021-0603

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
In onCreate of ContactSelectionActivity.java, there is a possible way to get access to contacts without permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-182809425
Attacker Value
Unknown

CVE-2021-0586

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
In onCreate of DevicePickerFragment.java, there is a possible way to trick the user to select an unwanted bluetooth device due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.1 Android-9 Android-10Android ID: A-182584940
Attacker Value
Unknown

CVE-2021-35300

Disclosure Date: June 28, 2021 (last updated February 22, 2025)
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users into visiting the attackers' page.