|
211451
|
5.5 |
MEDIUM
Local
|
apple debian
|
mac_os_x debian_linux
|
An input validation issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious appli…
|
CWE-20
Improper Input Validation
|
CVE-2020-10001
|
2024-11-21 13:54 |
2021-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211452
|
5.5 |
MEDIUM
Local
|
siemens
|
simatic_pcs_7 simatic_wincc
|
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password p…
|
CWE-287
Improper Authentication
|
CVE-2020-10048
|
2024-11-21 13:54 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211453
|
8.1 |
HIGH
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-…
|
CWE-78
OS Command
|
CVE-2020-10209
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211454
|
9.9 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute a…
|
CWE-78 CWE-74
OS Command Injection
|
CVE-2020-10208
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211455
|
4.4 |
MEDIUM
Local
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows local attackers to view and interact w…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10206
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211456
|
9.8 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series, Kami7B, an attacker may remotely log in through …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10210
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211457
|
9.8 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve an…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10207
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211458
|
9.8 |
CRITICAL
Network
|
solarwinds
|
orion_platform
|
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authenticatio…
|
CWE-287
Improper Authentication
|
CVE-2020-10148
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211459
|
7.8 |
HIGH
Local
|
macrium
|
reflect
|
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivilege…
|
CWE-665
Improper Initialization
|
CVE-2020-10143
|
2024-11-21 13:54 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211460
|
5.4 |
MEDIUM
Network
|
microsoft
|
teams
|
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as aut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10146
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|