|
200081
|
9.8 |
CRITICAL
Network
|
dset_project
|
dset
|
Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28277
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200082
|
9.8 |
CRITICAL
Network
|
deep-set_project
|
deep-set
|
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-noinfo
|
CVE-2020-28276
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200083
|
6.8 |
MEDIUM
Physics
|
foscammall
|
foscam_x1_firmware
|
FOSCAM FHD X1 1.14.2.4 devices allow attackers (with physical UART access) to login via the ipc.fos~ password.
|
NVD-CWE-noinfo
|
CVE-2020-28096
|
2024-11-21 14:22 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200084
|
7.5 |
HIGH
Network
|
tendacn
|
ac1200_firmware
|
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, the default settings for the router speed test contain links to download malware named elive or CNKI E-Learning.
|
NVD-CWE-noinfo
|
CVE-2020-28094
|
2024-11-21 14:22 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200085
|
7.2 |
HIGH
Network
|
tendacn
|
ac1200_firmware
|
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, admin, support, user, and nobody have a password of 1234.
|
NVD-CWE-noinfo
|
CVE-2020-28093
|
2024-11-21 14:22 |
2020-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200086
|
5.9 |
MEDIUM
Network
|
terra-master
|
tos
|
TerraMaster TOS <= 4.2.06 was found to check for updates (of both system and applications) via an insecure channel (HTTP). Man-in-the-middle attackers are able to intercept these requests and serve a…
|
NVD-CWE-noinfo
|
CVE-2020-28190
|
2024-11-21 14:22 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200087
|
9.8 |
CRITICAL
Network
|
terra-master
|
tos
|
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inject OS commands via /include/makecvs.php in Event parameter.
|
CWE-78
OS Command
|
CVE-2020-28188
|
2024-11-21 14:22 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200088
|
9.8 |
CRITICAL
Network
|
terra-master
|
tos
|
Multiple directory traversal vulnerabilities in TerraMaster TOS <= 4.2.06 allow remote authenticated attackers to read, edit or delete any file within the filesystem via the (1) filename parameter to…
|
CWE-22
Path Traversal
|
CVE-2020-28187
|
2024-11-21 14:22 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200089
|
7.3 |
HIGH
Network
|
terra-master
|
tos
|
Email Injection in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to abuse the forget password functionality and achieve account takeover.
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-28186
|
2024-11-21 14:22 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200090
|
5.3 |
MEDIUM
Network
|
terra-master
|
tos
|
User Enumeration vulnerability in TerraMaster TOS <= 4.2.06 allows remote unauthenticated attackers to identify valid users within the system via the username parameter to wizard/initialise.php.
|
NVD-CWE-noinfo
|
CVE-2020-28185
|
2024-11-21 14:22 |
2020-12-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|