|
211181
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
|
NVD-CWE-noinfo
|
CVE-2020-14103
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211182
|
8.1 |
HIGH
Network
|
mi
|
ax3600_firmware
|
A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.
|
CWE-362
Race Condition
|
CVE-2020-14104
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211183
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-14099
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211184
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation cod…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13963
|
2024-11-21 14:02 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211185
|
7.5 |
HIGH
Network
|
apache
|
ambari
|
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
|
CWE-22
Path Traversal
|
CVE-2020-13924
|
2024-11-21 14:02 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211186
|
6.1 |
MEDIUM
Network
|
apache debian
|
velocity_tools debian_linux
|
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13959
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211187
|
8.8 |
HIGH
Network
|
apache debian oracle
|
velocity_engine wss4j debian_linux retail_order_broker banking_platform communications_network_integrity banking_enterprise_default_management banking_party_management utiliti…
|
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appl…
|
NVD-CWE-noinfo
|
CVE-2020-13936
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211188
|
7.5 |
HIGH
Network
|
apache oracle
|
thrift hive communications_cloud_native_core_network_slice_selection_function communications_cloud_native_core_policy
|
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13949
|
2024-11-21 14:02 |
2021-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211189
|
6.1 |
MEDIUM
Network
|
apache oracle
|
activemq communications_session_route_manager communications_session_report_manager
|
An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13947
|
2024-11-21 14:02 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211190
|
5.9 |
MEDIUM
Network
|
fedoraproject
|
fedora
|
A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queri…
|
NVD-CWE-Other
|
CVE-2020-14312
|
2024-11-21 14:02 |
2021-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|