|
210081
|
9.8 |
CRITICAL
Network
|
mi
|
r3600_firmware
|
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability.
|
CWE-77
Command Injection
|
CVE-2020-14100
|
2024-11-21 14:02 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210082
|
9.8 |
CRITICAL
Network
|
mi
|
xiaomi_ai_speaker_firmware
|
Memory overflow in Xiaomi AI speaker Rom version <1.59.6 can happen when the speaker verifying a malicious firmware during OTA process.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-14096
|
2024-11-21 14:02 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210083
|
7.5 |
HIGH
Network
|
bitcoin
|
bitcoin_core
|
Bitcoin Core 0.20.0 allows remote denial of service.
|
NVD-CWE-noinfo
|
CVE-2020-14198
|
2024-11-21 14:02 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210084
|
5.9 |
MEDIUM
Network
|
apache oracle debian
|
activemq flexcube_private_banking communications_diameter_signaling_router debian_linux
|
Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and ca…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13920
|
2024-11-21 14:02 |
2020-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210085
|
5.7 |
MEDIUM
Adjacent
|
health
|
covidsafe
|
In the COVIDSafe application through 1.0.21 for Android, unsafe use of the Bluetooth transport option in the GATT connection allows attackers to trick the application into establishing a connection o…
|
NVD-CWE-noinfo
|
CVE-2020-14292
|
2024-11-21 14:02 |
2020-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210086
|
7.2 |
HIGH
Network
|
zohocorp
|
manageengine_applications_manager
|
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in a specific location, which leads to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-14008
|
2024-11-21 14:02 |
2020-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210087
|
6.1 |
MEDIUM
Network
|
enghouse
|
web_chat
|
Enghouse Web Chat 6.2.284.34 allows XSS. When one enters their own domain name in the WebServiceLocation parameter, the response from the POST request is displayed, and any JavaScript returned from t…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13972
|
2024-11-21 14:02 |
2020-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210088
|
8.8 |
HIGH
Network
|
dolibarr
|
dolibarr
|
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-14209
|
2024-11-21 14:02 |
2020-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210089
|
5.9 |
MEDIUM
Network
|
apache netapp
|
cassandra oncommand_insight
|
In Apache Cassandra, all versions prior to 2.1.22, 2.2.18, 3.0.22, 3.11.8 and 4.0-beta2, it is possible for a local attacker without access to the Apache Cassandra process or configuration files to m…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-13946
|
2024-11-21 14:02 |
2020-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210090
|
7.5 |
HIGH
Network
|
atlassian
|
jira jira_software_data_center jira_server jira_data_center
|
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affecte…
|
NVD-CWE-noinfo
|
CVE-2020-14178
|
2024-11-21 14:02 |
2020-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|