|
209991
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800…
|
CWE-662
Improper Synchronization
|
CVE-2020-14098
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209992
|
7.5 |
HIGH
Network
|
mi
|
redmi_ax6_firmware
|
Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.
|
NVD-CWE-noinfo
|
CVE-2020-14097
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209993
|
9.8 |
CRITICAL
Network
|
hcltechsw
|
hcl_commerce
|
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unau…
|
NVD-CWE-noinfo
|
CVE-2020-14275
|
2024-11-21 14:02 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209994
|
7.5 |
HIGH
Network
|
hcltechsw
|
hcl_commerce
|
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2020-14274
|
2024-11-21 14:02 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209995
|
6.5 |
MEDIUM
Network
|
apache
|
dolphinscheduler
|
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13922
|
2024-11-21 14:02 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209996
|
7.5 |
HIGH
Network
|
hcltech
|
domino
|
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to c…
|
CWE-20
Improper Input Validation
|
CVE-2020-14273
|
2024-11-21 14:02 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209997
|
6.1 |
MEDIUM
Network
|
crk
|
business_platform
|
CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13969
|
2024-11-21 14:02 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209998
|
9.8 |
CRITICAL
Network
|
crk
|
business_platform
|
CRK Business Platform <= 2019.1 allows can inject SQL statements against the DB on any path using the 'strSessao' parameter.
|
CWE-89
SQL Injection
|
CVE-2020-13968
|
2024-11-21 14:02 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209999
|
5.3 |
MEDIUM
Network
|
hcltech
|
domino
|
HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthenticated attacker could exploit this vulnerability …
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-14270
|
2024-11-21 14:02 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210000
|
8.8 |
HIGH
Network
|
hcltechsw
|
hcl_client_application_access
|
A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow …
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-14231
|
2024-11-21 14:02 |
2020-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|