|
211751
|
9.8 |
CRITICAL
Network
|
codologic
|
codoforum
|
A SQL Injection vulnerability in get_topic_info() in sys/CODOF/Forum/Topic.php in Codoforum before 4.9 allows remote attackers (pre-authentication) to bypass the admin page via a leaked password-rese…
|
CWE-89
SQL Injection
|
CVE-2020-13873
|
2024-11-21 14:02 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211752
|
6.3 |
MEDIUM
Network
|
proofpoint
|
enterprise_protection
|
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-14009
|
2024-11-21 14:02 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211753
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
|
NVD-CWE-noinfo
|
CVE-2020-14105
|
2024-11-21 14:02 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211754
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.
|
CWE-863
Incorrect Authorization
|
CVE-2020-14106
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211755
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
|
NVD-CWE-noinfo
|
CVE-2020-14103
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211756
|
8.1 |
HIGH
Network
|
mi
|
ax3600_firmware
|
A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.
|
CWE-362
Race Condition
|
CVE-2020-14104
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211757
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-14099
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211758
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation cod…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13963
|
2024-11-21 14:02 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211759
|
7.5 |
HIGH
Network
|
apache
|
ambari
|
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
|
CWE-22
Path Traversal
|
CVE-2020-13924
|
2024-11-21 14:02 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211760
|
6.1 |
MEDIUM
Network
|
apache debian
|
velocity_tools debian_linux
|
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13959
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|