|
196381
|
9.8 |
CRITICAL
Network
|
kmccontrols
|
bac-a1616bc_firmware
|
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME variable in the BC_Logon.swf file.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-7233
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196382
|
7.5 |
HIGH
Network
|
evoko
|
home
|
Evoko Home devices 1.31 through 1.37 allow remote attackers to obtain sensitive information (such as usernames and password hashes) via a WebSocket request, as demonstrated by the sockjs/224/uf1psgff…
|
NVD-CWE-noinfo
|
CVE-2020-7232
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196383
|
5.3 |
MEDIUM
Network
|
evoko
|
home
|
Evoko Home 1.31 devices provide different error messages for failed login requests depending on whether the username is valid.
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-7231
|
2024-11-21 14:36 |
2020-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196384
|
6.5 |
MEDIUM
Network
|
westermo
|
mrd-315_firmware
|
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web applic…
|
NVD-CWE-noinfo
|
CVE-2020-7227
|
2024-11-21 14:36 |
2020-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196385
|
5.3 |
MEDIUM
Network
|
amcrest
|
web_server
|
An issue was discovered in Amcrest Web Server 2.520.AC00.18.R 2017-06-29 WEB 3.2.1.453504. The login page responds with JavaScript when one tries to authenticate. An attacker who changes the result p…
|
CWE-287
Improper Authentication
|
CVE-2020-7222
|
2024-11-21 14:36 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196386
|
8.8 |
HIGH
Network
|
meinbergglobal
|
lantime_m300_firmware lantime_m1000_firmware
|
Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /config/netconf.cmd script (aka Extended Network Config…
|
CWE-78
OS Command
|
CVE-2020-7240
|
2024-11-21 14:36 |
2020-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196387
|
6.1 |
MEDIUM
Network
|
kibokolabs
|
chained_quiz
|
The chained-quiz plugin 1.1.8.1 for WordPress has reflected XSS via the wp-admin/admin-ajax.php total_questions parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7104
|
2024-11-21 14:36 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196388
|
5.3 |
MEDIUM
Network
|
zte
|
f6x2w_firmware
|
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could log in directly to obtain page information without entering a verification code.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-6862
|
2024-11-21 14:36 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196389
|
5.6 |
MEDIUM
Network
|
libslirp_project debian opensuse qemu
|
libslirp debian_linux leap qemu
|
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds a…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7039
|
2024-11-21 14:36 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196390
|
9.1 |
CRITICAL
Network
|
webfactoryltd
|
wp_database_reset
|
The WordPress plugin, WP Database Reset through 3.1, contains a flaw that allowed any unauthenticated user to reset any table in the database to the initial WordPress set-up state (deleting all site …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7048
|
2024-11-21 14:36 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|