|
199711
|
9.8 |
CRITICAL
Network
|
getobject_project
|
getobject
|
Prototype pollution vulnerability in 'getobject' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-Other
|
CVE-2020-28282
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199712
|
9.8 |
CRITICAL
Network
|
set-object-value_project
|
set-object-value
|
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28281
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199713
|
9.8 |
CRITICAL
Network
|
predefine_project
|
predefine
|
Prototype pollution vulnerability in 'predefine' versions 0.0.0 through 0.1.2 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28280
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199714
|
9.8 |
CRITICAL
Network
|
flattenizer_project
|
flattenizer
|
Prototype pollution vulnerability in 'flattenizer' versions 0.0.5 through 1.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28279
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199715
|
9.8 |
CRITICAL
Network
|
shvl_project
|
shvl
|
Prototype pollution vulnerability in 'shvl' versions 1.0.0 through 2.0.1 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28278
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199716
|
9.8 |
CRITICAL
Network
|
dset_project
|
dset
|
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28277
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199717
|
9.8 |
CRITICAL
Network
|
deep-set_project
|
deep-set
|
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28276
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199718
|
6.8 |
MEDIUM
Physics
|
foscammall
|
foscam_x1_firmware
|
FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.
|
NVD-CWE-noinfo
|
CVE-2020-28096
|
2024-11-21 14:22 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199719
|
7.5 |
HIGH
Network
|
tendacn
|
ac1200_firmware
|
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.
|
NVD-CWE-noinfo
|
CVE-2020-28094
|
2024-11-21 14:22 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199720
|
7.2 |
HIGH
Network
|
tendacn
|
ac1200_firmware
|
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.
|
NVD-CWE-noinfo
|
CVE-2020-28093
|
2024-11-21 14:22 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|