|
197131
|
7.3 |
HIGH
Adjacent
|
mi
|
miui_firmware
|
An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. In the Web resources of GetApps(com.xiaomi.mipicks), the parameters passed in are read and executed. After reading the resource files…
|
NVD-CWE-noinfo
|
CVE-2020-9531
|
2024-11-21 14:40 |
2020-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197132
|
7.8 |
HIGH
Local
|
redsoftware
|
pdfescape
|
An untrusted search path vulnerability in the installer of PDFescape Desktop version 4.0.22 and earlier allows an attacker to gain privileges and execute code via DLL hijacking.
|
CWE-426
Untrusted Search Path
|
CVE-2020-9418
|
2024-11-21 14:40 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197133
|
7.5 |
HIGH
Network
|
d-link
|
dsl-2640b_firmware
|
An issue was discovered on D-Link DSL-2640B E1 EU_1.01 devices. The administrative interface doesn't perform authentication checks for a firmware-update POST request. Any attacker that can access the…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-9544
|
2024-11-21 14:40 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197134
|
8.8 |
HIGH
Network
|
djangoproject debian fedoraproject netapp canonical
|
django debian_linux fedora steelstore_cloud_integrated_storage ubuntu_linux
|
Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui…
|
CWE-89
SQL Injection
|
CVE-2020-9402
|
2024-11-21 14:40 |
2020-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197135
|
9.8 |
CRITICAL
Network
|
whmcssmarters
|
web_tv_player
|
IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-9380
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197136
|
9.1 |
CRITICAL
Network
|
humaxdigital
|
hga12r-02_firmware
|
HUMAX HGA12R-02 BRGCAA 1.1.53 devices allow Session Hijacking.
|
CWE-384
Session Fixation
|
CVE-2020-9370
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197137
|
9.8 |
CRITICAL
Network
|
rubetek
|
smarthome_firmware
|
Rubetek SmartHome 2020 devices use unencrypted 433 MHz communication between controllers and beacons, allowing an attacker to sniff and spoof beacon requests remotely.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-9550
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197138
|
9.8 |
CRITICAL
Network
|
humaxdigital
|
hga12r-02_firmware
|
An issue was discovered on HUMAX HGA12R-02 BRGCAA 1.1.53 devices. A vulnerability in the authentication functionality in the web-based interface could allow an unauthenticated remote attacker to capt…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-9477
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197139
|
7.5 |
HIGH
Network
|
commscope
|
arris_tg1692a_firmware
|
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-9476
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197140
|
7.8 |
HIGH
Local
|
codepeople
|
appointment_booking_calendar
|
The Appointment Booking Calendar plugin before 1.3.35 for WordPress allows user input (in fields such as Description or Name) in any booking form to be any formula, which then could be exported via t…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-9372
|
2024-11-21 14:40 |
2020-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|