|
196901
|
7.8 |
HIGH
Local
|
grunt-util-property_project
|
grunt-util-property
|
This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7641
|
2024-11-21 14:37 |
2022-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196902
|
8.8 |
HIGH
Network
|
schneider-electric
|
modicon_m340_bmxp342020_firmware 140cpu65_firmware tsxp57_firmware bmxnoc0401_firmware bmxnoe01_firmware bmxnor0200h_firmware 140noe77111_firmware 140noc78000_firmware tsxety5…
|
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists on the web server used, that could cause a leak of sensitive data or unauthorized actions on the web server during the time the user …
|
CWE-352
Origin Validation Error
|
CVE-2020-7534
|
2024-11-21 14:37 |
2022-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196903
|
9.8 |
CRITICAL
Network
|
wowsoft
|
printchaser
|
Printchaser v2.2021.804.1 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. …
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7883
|
2024-11-21 14:37 |
2021-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196904
|
9.8 |
CRITICAL
Network
|
4nb
|
videooffice
|
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and earlier versions (CVE-2020-7878). This issue is due to missing support for integrity check.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2020-7878
|
2024-11-21 14:37 |
2021-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196905
|
8.8 |
HIGH
Network
|
douzone
|
neors
|
The vulnerabilty was discovered in ActiveX module related to NeoRS remote support program. This issue allows an remote attacker to download and execute remote file. It is because of improper paramete…
|
CWE-20
Improper Input Validation
|
CVE-2020-7880
|
2024-11-21 14:37 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196906
|
9.8 |
CRITICAL
Network
|
iptime
|
c200_firmware
|
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE…
|
CWE-78
OS Command
|
CVE-2020-7879
|
2024-11-21 14:37 |
2021-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196907
|
8.8 |
HIGH
Network
|
afreecatv
|
afreecatv
|
The vulnerability function is enabled when the streamer service related to the AfreecaTV communicated through web socket using 21201 port. A stack-based buffer overflow leading to remote code executi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7881
|
2024-11-21 14:37 |
2021-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196908
|
9.1 |
CRITICAL
Network
|
hancom
|
anysign4pc
|
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal charac…
|
CWE-22
Path Traversal
|
CVE-2020-7882
|
2024-11-21 14:37 |
2021-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196909
|
8.8 |
HIGH
Network
|
dext5
|
dext5upload
|
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. Thi…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7875
|
2024-11-21 14:37 |
2021-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196910
|
7.8 |
HIGH
Local
|
helpu
|
helpuviewer
|
An improper input validation vulnerability in Helpu solution could allow a local attacker to arbitrary file creation and execution without click file transfer menu. It is possible to file in arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2020-7867
|
2024-11-21 14:37 |
2021-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|