|
211121
|
9.8 |
CRITICAL
Network
|
szuray jtechdigital provideoinstruments
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware h.264_iptv_encoder_1080p\@60hz_firmware vecaster-hd-h264_firmware vecaster-hd-hevc_firmware vecaster-4k-hevc_firmw…
|
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-24217
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211122
|
7.5 |
HIGH
Network
|
szuray jtechdigital provideoinstruments
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware h.264_iptv_encoder_1080p\@60hz_firmware vecaster-hd-h264_firmware vecaster-hd-hevc_firmware vecaster-4k-hevc_firmw…
|
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via…
|
NVD-CWE-noinfo
|
CVE-2020-24216
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211123
|
6.1 |
MEDIUM
Network
|
car_rental_management_system_project
|
car_rental_management_system
|
A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23832
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211124
|
9.8 |
CRITICAL
Network
|
szuray jtechdigital provideoinstruments
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware h.264_iptv_encoder_1080p\@60hz_firmware vecaster-hd-h264_firmware vecaster-hd-hevc_firmware vecaster-4k-hevc_firmw…
|
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use hard-coded credentials in HTTP requests to perform any administrative task on the …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-24215
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211125
|
9.8 |
CRITICAL
Network
|
szuray jtechdigital provideoinstruments
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware h.264_iptv_encoder_1080p\@60hz_firmware vecaster-hd-h264_firmware vecaster-hd-hevc_firmware vecaster-4k-hevc_firmw…
|
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a crafted unauthenticated RTSP request to cause a buffer overflow and application…
|
NVD-CWE-Other
|
CVE-2020-24214
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211126
|
9.8 |
CRITICAL
Network
|
jumpmind
|
symmetricds
|
Symmetric DS <3.12.0 uses mx4j to provide access to JMX over HTTP. mx4j, by default, has no auth and is available on all interfaces. An attacker can interact with JMX: get system info, and invoke MBe…
|
NVD-CWE-noinfo
|
CVE-2020-24231
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211127
|
7.2 |
HIGH
Network
|
zohocorp
|
manageengine_desktop_central
|
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.0.SP-534. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendR…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-24397
|
2024-11-21 14:14 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211128
|
7.8 |
HIGH
Local
|
cloudflare
|
cloudflared
|
`cloudflared` versions prior to 2020.8.1 contain a local privilege escalation vulnerability on Windows systems. When run on a Windows system, `cloudflared` searches for configuration files which coul…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-24356
|
2024-11-21 14:14 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211129
|
7.8 |
HIGH
Local
|
trendmicro
|
apex_one
|
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege e…
|
CWE-287
Improper Authentication
|
CVE-2020-24563
|
2024-11-21 14:14 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211130
|
7.8 |
HIGH
Local
|
trendmicro
|
officescan
|
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escala…
|
CWE-59
Link Following
|
CVE-2020-24562
|
2024-11-21 14:14 |
2020-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|