|
209381
|
7.8 |
HIGH
Local
|
mi
|
ax3600_firmware
|
AX3600 router sensitive information leaked.There is an unauthorized interface through luci to obtain sensitive information and log in to the web background.
|
CWE-863
Incorrect Authorization
|
CVE-2020-14110
|
2024-11-21 14:02 |
2022-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209382
|
7.5 |
HIGH
Network
|
mi
|
xiaomi_mirror_screen
|
A stack overflow in the HTTP server of Cast can be exploited to make the app crash in LAN.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-14107
|
2024-11-21 14:02 |
2022-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209383
|
3.9 |
LOW
Physics
|
hcltech
|
traveler_companion
|
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-14264
|
2024-11-21 14:02 |
2021-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209384
|
3.9 |
LOW
Physics
|
hcltech
|
traveler_companion
|
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-14263
|
2024-11-21 14:02 |
2021-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209385
|
9.8 |
CRITICAL
Network
|
mi
|
ax3600_firmware
|
There is a buffer overflow in librsa.so called by getwifipwdurl interface, resulting in code execution on Xiaomi router AX3600 with ROM version =rom< 1.1.12.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-14124
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209386
|
9.8 |
CRITICAL
Network
|
mi
|
ax3600
|
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under administrator authority on Xiaomi router AX3600 with rom versionrom< 1.1.12
|
CWE-77
Command Injection
|
CVE-2020-14119
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209387
|
5.3 |
MEDIUM
Network
|
mi
|
xiaomi
|
Some js interfaces in the Xiaomi community were exposed, causing sensitive functions to be maliciously called on Xiaomi community app Affected Version <3.0.210809
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-14130
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209388
|
7.2 |
HIGH
Network
|
mi
|
ax3600_firmware
|
There is command injection in the meshd program in the routing system, resulting in command execution under administrator authority on Xiaomi router AX3600 with ROM version =< 1.1.12
|
CWE-77
Command Injection
|
CVE-2020-14109
|
2024-11-21 14:02 |
2021-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209389
|
7.5 |
HIGH
Network
|
apache
|
zeppelin
|
Authentication bypass vulnerability in Apache Zeppelin allows an attacker to bypass Zeppelin authentication mechanism to act as another user. This issue affects Apache Zeppelin Apache Zeppelin versio…
|
NVD-CWE-noinfo
|
CVE-2020-13929
|
2024-11-21 14:02 |
2021-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209390
|
6.1 |
MEDIUM
Network
|
thecodingmachine
|
gotenberg
|
It is possible to inject HTML and/or JavaScript in the HTML to PDF conversion in Gotenberg through 6.2.1 via the /convert/html endpoint.
|
CWE-79
Cross-site Scripting
|
CVE-2020-14161
|
2024-11-21 14:02 |
2021-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|