|
211411
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-21342
|
2024-11-21 14:12 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211412
|
8.8 |
HIGH
Network
|
iwt
|
facesentry_access_control_system_firmware
|
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell …
|
CWE-78
OS Command
|
CVE-2020-21999
|
2024-11-21 14:12 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211413
|
9.8 |
CRITICAL
Network
|
uniview
|
isc2500-s_firmware
|
An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC.php?cmd=upload
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21452
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211414
|
5.4 |
MEDIUM
Network
|
screenly
|
screenly
|
Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could l…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21101
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211415
|
7.5 |
HIGH
Network
|
smartwares
|
home_easy_firmware
|
Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information res…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21997
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211416
|
9.8 |
CRITICAL
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-21995
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211417
|
8.8 |
HIGH
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called …
|
CWE-78
OS Command
|
CVE-2020-21992
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211418
|
7.5 |
HIGH
Network
|
domoticz
|
mydomoathome
|
Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote…
|
CWE-863
Incorrect Authorization
|
CVE-2020-21990
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211419
|
7.5 |
HIGH
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21996
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211420
|
9.8 |
CRITICAL
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xm…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-21994
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|