|
210341
|
5.5 |
MEDIUM
Local
|
qemu
|
qemu
|
An issue was discovered in QEMU through 5.1.0. An out-of-bounds memory access was found in the ATI VGA device implementation. This flaw occurs in the ati_2d_blt() routine in hw/display/ati_2d.c while…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-24352
|
2024-11-21 14:14 |
2020-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210342
|
6.1 |
MEDIUM
Network
|
unitedplanet
|
intrexx
|
Cross-site scripting (XSS) vulnerability in the search functionality in Intrexx before 9.4.0 allows remote attackers to inject arbitrary web script or HTML via the request parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24188
|
2024-11-21 14:14 |
2020-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210343
|
6.1 |
MEDIUM
Network
|
iproom
|
mmc\+
|
IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials.
|
CWE-601
Open Redirect
|
CVE-2020-24551
|
2024-11-21 14:14 |
2020-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210344
|
6.1 |
MEDIUM
Network
|
hapifhir
|
testpage_overlay
|
Users of the HAPI FHIR Testpage Overlay 5.0.0 and below can use a specially crafted URL to exploit an XSS vulnerability in this module, allowing arbitrary JavaScript to be executed in the user's brow…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24301
|
2024-11-21 14:14 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210345
|
7.5 |
HIGH
Network
|
peplink
|
balance_20x_firmware balance_310x_firmware mbx_firmware epx_firmware sdx_firmware balance_30_lte_firmware balance_20_firmware balance_30_firmware balance_30_pro_firmware ba…
|
Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin.
|
NVD-CWE-noinfo
|
CVE-2020-24246
|
2024-11-21 14:14 |
2020-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210346
|
7.5 |
HIGH
Network
|
szuray
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware
|
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming f…
|
CWE-22
Path Traversal
|
CVE-2020-24219
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210347
|
9.8 |
CRITICAL
Network
|
szuray
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware
|
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can log in as root via the password that is hard-coded in the executable file.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-24218
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210348
|
9.8 |
CRITICAL
Network
|
szuray jtechdigital provideoinstruments
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware h.264_iptv_encoder_1080p\@60hz_firmware vecaster-hd-h264_firmware vecaster-hd-hevc_firmware vecaster-4k-hevc_firmw…
|
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpoint does not enforce authentication. Attackers can send an unauthenticated HTTP…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-24217
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210349
|
7.5 |
HIGH
Network
|
szuray jtechdigital provideoinstruments
|
iptv\/h.264_video_encoder_firmware iptv\/h.265_video_encoder_firmware h.264_iptv_encoder_1080p\@60hz_firmware vecaster-hd-h264_firmware vecaster-hd-hevc_firmware vecaster-4k-hevc_firmw…
|
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. When the administrator configures a secret URL for RTSP streaming, the stream is still available via…
|
NVD-CWE-noinfo
|
CVE-2020-24216
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210350
|
6.1 |
MEDIUM
Network
|
car_rental_management_system_project
|
car_rental_management_system
|
A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session…
|
CWE-79
Cross-site Scripting
|
CVE-2020-23832
|
2024-11-21 14:14 |
2020-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|