|
210681
|
8.8 |
HIGH
Network
|
gnu
|
libredwg
|
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21814
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210682
|
7.8 |
HIGH
Local
|
gnu
|
libredwg
|
A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-21813
|
2024-11-21 14:12 |
2021-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210683
|
7.5 |
HIGH
Network
|
zzcms
|
zzcms
|
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-21342
|
2024-11-21 14:12 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210684
|
8.8 |
HIGH
Network
|
iwt
|
facesentry_access_control_system_firmware
|
iWT Ltd FaceSentry Access Control System 6.4.8 suffers from an authenticated OS command injection vulnerability using default credentials. This can be exploited to inject and execute arbitrary shell …
|
CWE-78
OS Command
|
CVE-2020-21999
|
2024-11-21 14:12 |
2021-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210685
|
9.8 |
CRITICAL
Network
|
uniview
|
isc2500-s_firmware
|
An issue was discovered in uniview ISC2500-S. This is an upload vulnerability where an attacker can upload malicious code via /Interface/DevManage/EC.php?cmd=upload
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-21452
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210686
|
5.4 |
MEDIUM
Network
|
screenly
|
screenly
|
Cross Site Scriptiong vulnerabilityin Screenly screenly-ose all versions, including v1.8.2 (2019-09-25-Screenly-OSE-lite.img), in the 'Add Asset' page via manipulation of a 'URL' field, which could l…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21101
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210687
|
7.5 |
HIGH
Network
|
smartwares
|
home_easy_firmware
|
Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information res…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21997
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210688
|
9.8 |
CRITICAL
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-21995
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210689
|
8.8 |
HIGH
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called …
|
CWE-78
OS Command
|
CVE-2020-21992
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210690
|
7.5 |
HIGH
Network
|
domoticz
|
mydomoathome
|
Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote…
|
CWE-863
Incorrect Authorization
|
CVE-2020-21990
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|