|
209211
|
9.8 |
CRITICAL
Network
|
company
|
cs-c2shw_firmware
|
Bash injection vulnerability and bypass of signature verification in Rostelecom CS-C2SHW 5.0.082.1. The camera reads firmware update configuration from SD card file vc\version.json. fw-sign parameter…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-27540
|
2024-11-21 14:21 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209212
|
6.8 |
MEDIUM
Physics
|
company
|
cs-c2shw_firmware
|
Rostelecom CS-C2SHW 5.0.082.1 is affected by: Bash command injection. The camera reads configuration from QR code (including network settings). The static IP configuration from QR code is copied to t…
|
CWE-78
OS Command
|
CVE-2020-27542
|
2024-11-21 14:21 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209213
|
9.8 |
CRITICAL
Network
|
company
|
cs-c2shw_firmware
|
Heap overflow with full parsing of HTTP respose in Rostelecom CS-C2SHW 5.0.082.1. AgentUpdater service has a self-written HTTP parser and builder. HTTP parser has a heap buffer overflow (OOB write). …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27539
|
2024-11-21 14:21 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209214
|
6.5 |
MEDIUM
Adjacent
|
philips
|
viewforum coronary_tools dynamic_coronary_roadmap stentboost_live interventional_workspot
|
Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software construc…
|
CWE-78
OS Command
|
CVE-2020-27298
|
2024-11-21 14:21 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209215
|
7.8 |
HIGH
Local
|
deltaww
|
tpeditor
|
An untrusted pointer dereference has been identified in the way TPEditor(v1.98 and prior) processes project files, allowing an attacker to craft a special project file that may permit arbitrary code …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27288
|
2024-11-21 14:21 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209216
|
7.5 |
HIGH
Network
|
nec
|
esmpro_manager
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The sp…
|
CWE-22
Path Traversal
|
CVE-2020-27859
|
2024-11-21 14:21 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209217
|
5.4 |
MEDIUM
Network
|
rocketgenius
|
gravityforms
|
A stored Cross-Site Scripting (XSS) vulnerability in the survey feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via a textarea field…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27852
|
2024-11-21 14:21 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209218
|
5.4 |
MEDIUM
Network
|
rocketgenius
|
gravityforms
|
Multiple stored HTML injection vulnerabilities in the "poll" and "quiz" features in an additional paid add-on of Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary H…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27851
|
2024-11-21 14:21 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209219
|
4.8 |
MEDIUM
Network
|
rocketgenius
|
gravityforms
|
A stored Cross-Site Scripting (XSS) vulnerability in forms import feature in Rocketgenius Gravity Forms before 2.4.21 allows remote attackers to inject arbitrary web script or HTML via the import of …
|
CWE-79
Cross-site Scripting
|
CVE-2020-27850
|
2024-11-21 14:21 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209220
|
7.5 |
HIGH
Network
|
arcserve
|
d2d
|
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not required to exploit this vulnerability. The speci…
|
CWE-611
XXE
|
CVE-2020-27858
|
2024-11-21 14:21 |
2021-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|