|
210401
|
9.9 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute a…
|
CWE-78 CWE-74
OS Command Injection
|
CVE-2020-10208
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210402
|
4.4 |
MEDIUM
Local
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows local attackers to view and interact w…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10206
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210403
|
9.8 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series, Kami7B, an attacker may remotely log in through …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10210
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210404
|
9.8 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve an…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10207
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210405
|
9.8 |
CRITICAL
Network
|
solarwinds
|
orion_platform
|
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authenticatio…
|
CWE-287
Improper Authentication
|
CVE-2020-10148
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210406
|
7.8 |
HIGH
Local
|
macrium
|
reflect
|
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivilege…
|
CWE-665
Improper Initialization
|
CVE-2020-10143
|
2024-11-21 13:54 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210407
|
5.4 |
MEDIUM
Network
|
microsoft
|
teams
|
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as aut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10146
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210408
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x tvos iphone_os watchos ipados
|
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted au…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10017
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210409
|
7.8 |
HIGH
Local
|
apple
|
tvos iphone_os watchos ipados mac_os_x macos
|
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. An application may be able to ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10016
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210410
|
6.3 |
MEDIUM
Local
|
apple
|
macos mac_os_x
|
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sa…
|
CWE-22
Path Traversal
|
CVE-2020-10014
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|