|
211091
|
6.3 |
MEDIUM
Network
|
proofpoint
|
enterprise_protection
|
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-14009
|
2024-11-21 14:02 |
2021-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211092
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
|
NVD-CWE-noinfo
|
CVE-2020-14105
|
2024-11-21 14:02 |
2021-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211093
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can unauthorized access to the list of running processes in the mobile phone, Xiaomi Mobile Phone MIUI < 2021.01.26.
|
CWE-863
Incorrect Authorization
|
CVE-2020-14106
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211094
|
5.5 |
MEDIUM
Local
|
mi
|
miui
|
The application in the mobile phone can read the SNO information of the device, Xiaomi 10 MIUI < 2020.01.15.
|
NVD-CWE-noinfo
|
CVE-2020-14103
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211095
|
8.1 |
HIGH
Network
|
mi
|
ax3600_firmware
|
A RACE CONDITION on XQBACKUP causes a decompression path error on Xiaomi router AX3600 with ROM version =1.0.50.
|
CWE-362
Race Condition
|
CVE-2020-14104
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211096
|
7.5 |
HIGH
Network
|
mi
|
ax1800_firmware rm1800_firmware
|
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-14099
|
2024-11-21 14:02 |
2021-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211097
|
9.8 |
CRITICAL
Network
|
soplanning
|
soplanning
|
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and the related authentication algorithm, is public. The key for admin is hardcoded in the installation cod…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-13963
|
2024-11-21 14:02 |
2021-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211098
|
7.5 |
HIGH
Network
|
apache
|
ambari
|
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and traverse to other directories to download files.
|
CWE-22
Path Traversal
|
CVE-2020-13924
|
2024-11-21 14:02 |
2021-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211099
|
6.1 |
MEDIUM
Network
|
apache debian
|
velocity_tools debian_linux
|
The default error page for VelocityView in Apache Velocity Tools prior to 3.1 reflects back the vm file that was entered as part of the URL. An attacker can set an XSS payload file as this vm file in…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13959
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211100
|
8.8 |
HIGH
Network
|
apache debian oracle
|
velocity_engine wss4j debian_linux retail_order_broker banking_platform communications_network_integrity banking_enterprise_default_management banking_party_management utiliti…
|
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appl…
|
NVD-CWE-noinfo
|
CVE-2020-13936
|
2024-11-21 14:02 |
2021-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|