|
209951
|
3.9 |
LOW
Physics
|
hcltech
|
traveler_companion
|
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-14263
|
2024-11-21 14:02 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209952
|
9.8 |
CRITICAL
Network
|
mi
|
ax3600_firmware
|
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14124
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209953
|
9.8 |
CRITICAL
Network
|
mi
|
ax3600
|
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12
|
CWE-77
Command Injection
|
CVE-2020-14119
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209954
|
5.3 |
MEDIUM
Network
|
mi
|
xiaomi
|
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-14130
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209955
|
7.2 |
HIGH
Network
|
mi
|
ax3600_firmware
|
There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12
|
CWE-77
Command Injection
|
CVE-2020-14109
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209956
|
7.5 |
HIGH
Network
|
apache
|
zeppelin
|
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin versio…
|
NVD-CWE-noinfo
|
CVE-2020-13929
|
2024-11-21 14:02 |
2021-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209957
|
6.1 |
MEDIUM
Network
|
thecodingmachine
|
gotenberg
|
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14161
|
2024-11-21 14:02 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209958
|
7.5 |
HIGH
Network
|
thecodingmachine
|
gotenberg
|
An SSRF vulnerability in Gotenberg through 6.2.1 exists in the remote URL to PDF conversion, which results in a remote attacker being able to read local files or fetch intranet resources.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-14160
|
2024-11-21 14:02 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209959
|
9.8 |
CRITICAL
Network
|
asrock
|
box-r1000_firmware
|
ASRock 4x4 BOX-R1000 before BIOS P1.40 allows privilege escalation via code execution in the SMM.
|
CWE-269
Improper Privilege Management
|
CVE-2020-14032
|
2024-11-21 14:02 |
2021-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209960
|
7.5 |
HIGH
Network
|
apache debian fedoraproject oracle
|
http_server debian_linux fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit
|
Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, le…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13950
|
2024-11-21 14:02 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|