|
208801
|
9.8 |
CRITICAL
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
Inim Electronics Smartliving SmartLAN/G/SI <=6.x uses default hardcoded credentials. An attacker could exploit this to gain Telnet, SSH and FTP access to the system.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-21995
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208802
|
8.8 |
HIGH
Network
|
inim
|
smartliving_505_firmware smartliving_515_firmware smartliving_1050_firmware smartliving_1050g3_firmware smartliving_10100l_firmware smartliving_10100lg3_firmware
|
Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called …
|
CWE-78
OS Command
|
CVE-2020-21992
|
2024-11-21 14:12 |
2021-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208803
|
7.5 |
HIGH
Network
|
domoticz
|
mydomoathome
|
Emmanuel MyDomoAtHome (MDAH) REST API REST API Domoticz ISS Gateway 0.2.40 is affected by an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote…
|
CWE-863
Incorrect Authorization
|
CVE-2020-21990
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208804
|
7.5 |
HIGH
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-21996
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208805
|
9.8 |
CRITICAL
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from clear-text credentials disclosure vulnerability that allows an unauthenticated attacker to issue a request to an unprotected directory that hosts an XML file '/xm…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-21994
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208806
|
6.1 |
MEDIUM
Network
|
wems
|
enterprise_manager
|
In WEMS Limited Enterprise Manager 2.58, input passed to the GET parameter 'email' is not properly sanitized before being returned to the user. This can be exploited to execute arbitrary HTML code in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21993
|
2024-11-21 14:12 |
2021-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208807
|
9.8 |
CRITICAL
Network
|
ave
|
dominaplus 53ab-wbs_firmware ts01_firmware ts03x-v_firmware ts04x-v_firmware ts05_firmware ts05n-v_firmware
|
AVE DOMINAplus <=1.10.x suffers from an authentication bypass vulnerability due to missing control check when directly calling the autologin GET parameter in changeparams.php script. Setting the auto…
|
CWE-287
Improper Authentication
|
CVE-2020-21991
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208808
|
6.1 |
MEDIUM
Network
|
homeautomation_project
|
homeautomation
|
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an …
|
CWE-601
Open Redirect
|
CVE-2020-21998
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208809
|
8.8 |
HIGH
Network
|
homeautomation_project
|
homeautomation
|
HomeAutomation 3.3.2 is affected by Cross Site Request Forgery (CSRF). The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to ve…
|
CWE-352
Origin Validation Error
|
CVE-2020-21989
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208810
|
6.1 |
MEDIUM
Network
|
homeautomation_project
|
homeautomation
|
HomeAutomation 3.3.2 is affected by persistent Cross Site Scripting (XSS). XSS vulnerabilities occur when input passed via several parameters to several scripts is not properly sanitized before being…
|
CWE-79
Cross-site Scripting
|
CVE-2020-21987
|
2024-11-21 14:12 |
2021-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|