|
196951
|
7.8 |
HIGH
Local
|
voiceye_wsactivebridgees_project
|
voiceye_wsactivebridges
|
VOICEYE WSActiveBridgeES versions prior to 2.1.0.3 contains a stack-based buffer overflow vulnerability caused by improper bound checking parameter given by attack. It finally leads to a stack-based …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7836
|
2024-11-21 14:37 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196952
|
8.8 |
HIGH
Network
|
cnesty
|
helpcom
|
Helpcom before v10.0 contains a file download and execution vulnerability caused by storing hardcoded cryptographic key. It finally leads to a file download and execution via access to crafted web pa…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-7846
|
2024-11-21 14:37 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196953
|
8.0 |
HIGH
Adjacent
|
iptime
|
nas-i_firmware nas-ii_firmware nas-iie_firmware nas101_firmware nas1dual_firmware nas2dual_firmware nas3_firmware nas4_firmware nas4dual_firmware
|
The ipTIME NAS product allows an arbitrary file upload vulnerability in the Manage Bulletins/Upload feature, which can be leveraged to gain remote code execution. This issue affects: pTIME NAS 1.4.36.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-7847
|
2024-11-21 14:37 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196954
|
8.8 |
HIGH
Network
|
uprism
|
curix
|
A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability is due to insufficient input(server domain) valida…
|
CWE-20
Improper Input Validation
|
CVE-2020-7849
|
2024-11-21 14:37 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196955
|
8.0 |
HIGH
Adjacent
|
iptime
|
c200_firmware
|
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary…
|
CWE-77
Command Injection
|
CVE-2020-7848
|
2024-11-21 14:37 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196956
|
9.8 |
CRITICAL
Network
|
macfromip_project
|
macfromip
|
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
|
CWE-78
OS Command
|
CVE-2020-7786
|
2024-11-21 14:37 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196957
|
9.8 |
CRITICAL
Network
|
node-ps_project
|
node-ps
|
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
|
CWE-78
OS Command
|
CVE-2020-7785
|
2024-11-21 14:37 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196958
|
9.8 |
CRITICAL
Network
|
spritesheet-js_project
|
spritesheet-js
|
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main ent…
|
CWE-78
OS Command
|
CVE-2020-7782
|
2024-11-21 14:37 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196959
|
9.8 |
CRITICAL
Network
|
freediskspace_project
|
freediskproject
|
This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js.
|
CWE-78
OS Command
|
CVE-2020-7775
|
2024-11-21 14:37 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196960
|
5.5 |
MEDIUM
Local
|
mcafee
|
agent
|
Missing Authorization vulnerability in McAfee Agent (MA) for Windows prior to 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The …
|
CWE-862
Missing Authorization
|
CVE-2020-7343
|
2024-11-21 14:37 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|