|
209421
|
7.5 |
HIGH
Network
|
mofinetwork
|
mofi4500-4gxelte_firmware
|
An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. Authentication is not required to download the support file that contains sensitive information such as cleartext credentia…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13856
|
2024-11-21 14:02 |
2021-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209422
|
7.2 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and…
|
CWE-77
Command Injection
|
CVE-2020-14102
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209423
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
|
NVD-CWE-noinfo
|
CVE-2020-14101
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209424
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800…
|
CWE-662
Improper Synchronization
|
CVE-2020-14098
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209425
|
7.5 |
HIGH
Network
|
mi
|
redmi_ax6_firmware
|
Wrong nginx configuration, causing specific paths to be downloaded without authorization. This affects Xiaomi router AX6 ROM version < 1.0.18.
|
NVD-CWE-noinfo
|
CVE-2020-14097
|
2024-11-21 14:02 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209426
|
9.8 |
CRITICAL
Network
|
hcltechsw
|
hcl_commerce
|
Security vulnerability in HCL Commerce 9.0.0.5 through 9.0.0.13, 9.0.1.0 through 9.0.1.14 and 9.1 through 9.1.4 could allow denial of service, disclosure of user personal data, and performing of unau…
|
NVD-CWE-noinfo
|
CVE-2020-14275
|
2024-11-21 14:02 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209427
|
7.5 |
HIGH
Network
|
hcltechsw
|
hcl_commerce
|
Information disclosure vulnerability in HCL Commerce 9.0.1.9 through 9.0.1.14 and 9.1 through 9.1.4 could allow a remote attacker to obtain user personal data via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2020-14274
|
2024-11-21 14:02 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209428
|
6.5 |
MEDIUM
Network
|
apache
|
dolphinscheduler
|
Versions of Apache DolphinScheduler prior to 1.3.2 allowed an ordinary user under any tenant to override another users password through the API interface.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13922
|
2024-11-21 14:02 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209429
|
7.5 |
HIGH
Network
|
hcltech
|
domino
|
HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated attacker could could exploit this vulnerability to c…
|
CWE-20
Improper Input Validation
|
CVE-2020-14273
|
2024-11-21 14:02 |
2020-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209430
|
6.1 |
MEDIUM
Network
|
crk
|
business_platform
|
CRK Business Platform <= 2019.1 allows reflected XSS via erro.aspx on 'CRK', 'IDContratante', 'Erro', or 'Mod' parameter. This is path-independent.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13969
|
2024-11-21 14:02 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|