Show filters
325 Total Results
Displaying 101-110 of 325
Sort by:
Attacker Value
Unknown

CVE-2021-21803

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
Attacker Value
Unknown

CVE-2021-21802

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
Attacker Value
Unknown

CVE-2021-21799

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-21801

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
Attacker Value
Unknown

CVE-2021-21800

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerabilities exist in the ssh_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-33000

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Attacker Value
Unknown

CVE-2021-33002

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Attacker Value
Unknown

CVE-2021-33004

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
Attacker Value
Unknown

CVE-2021-32954

Disclosure Date: June 18, 2021 (last updated February 22, 2025)
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system.
Attacker Value
Unknown

CVE-2021-32956

Disclosure Date: June 18, 2021 (last updated February 22, 2025)
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage.