|
209981
|
7.5 |
HIGH
Network
|
hcltech
|
digital_experience
|
HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These affect containers only. These do not affect traditio…
|
NVD-CWE-noinfo
|
CVE-2020-14255
|
2024-11-21 14:02 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209982
|
4.9 |
MEDIUM
Network
|
hcltech
|
digital_experience
|
HCL Digital Experience 8.5, 9.0, and 9.5 exposes information about the server to unauthorized users.
|
NVD-CWE-noinfo
|
CVE-2020-14221
|
2024-11-21 14:02 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209983
|
4.3 |
MEDIUM
Network
|
atlassian
|
crucible fisheye
|
Affected versions of Atlassian Fisheye and Crucible allow remote attackers to view a product's SEN via an Information Disclosure vulnerability in the x-asen response header from Atlassian Analytics. …
|
CWE-200
Information Exposure
|
CVE-2020-14192
|
2024-11-21 14:02 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209984
|
7.5 |
HIGH
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. The one-time password algorithm for the undocumented system account mofidev generates a predictable six-digit password.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-13860
|
2024-11-21 14:02 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209985
|
9.8 |
CRITICAL
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the…
|
CWE-287 CWE-755
Improper Authentication Improper Handling of Exceptional Conditions
|
CVE-2020-13859
|
2024-11-21 14:02 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209986
|
9.8 |
CRITICAL
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They contain two undocumented administrator accounts. The sftp and mofidev accounts are defined in /etc/passw…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13858
|
2024-11-21 14:02 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209987
|
7.5 |
HIGH
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 3.6.1-std and 4.0.8-std devices. They can be rebooted by sending an unauthenticated poof.cgi HTTP GET request.
|
NVD-CWE-noinfo
|
CVE-2020-13857
|
2024-11-21 14:02 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209988
|
7.5 |
HIGH
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentia…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13856
|
2024-11-21 14:02 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209989
|
7.2 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and…
|
CWE-77
Command Injection
|
CVE-2020-14102
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209990
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
|
NVD-CWE-noinfo
|
CVE-2020-14101
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|