Show filters
733 Total Results
Displaying 241-250 of 733
Sort by:
Attacker Value
Unknown

CVE-2020-21997

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Smartwares HOME easy <=1.0.9 is vulnerable to an unauthenticated database backup download and information disclosure vulnerability. An attacker could disclose sensitive and clear-text information resulting in authentication bypass, session hijacking and full system control.
Attacker Value
Unknown

CVE-2021-21414

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this security vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. It only affects the `getPackedPackage` function and this function is not advertised and only used for tests & building our CLI, no malicious code was found after checking our codebase.
Attacker Value
Unknown

CVE-2021-28142

Disclosure Date: April 06, 2021 (last updated February 22, 2025)
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
Attacker Value
Unknown

CVE-2021-28935

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > My Preferences > Title field.
Attacker Value
Unknown

CVE-2020-19643

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B via all fields in the FTP settings page to the "goform/formSetFtpCfg" settings page.
Attacker Value
Unknown

CVE-2020-19640

Disclosure Date: March 30, 2021 (last updated November 28, 2024)
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. An unauthenticated attacker can reboot the device causing a Denial of Service, via a hidden reboot command to '/media/?action=cmd'.
Attacker Value
Unknown

CVE-2020-19641

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. Authenticated attackers with the "Operator" Privilege can gain admin privileges via a crafted request to '/goform/formUserMng'.
Attacker Value
Unknown

CVE-2020-19639

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
Cross Site Request Forgery (CSRF) vulnerability in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B, via all fields to WebUI.
Attacker Value
Unknown

CVE-2020-19642

Disclosure Date: March 30, 2021 (last updated February 22, 2025)
An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card.
Attacker Value
Unknown

CVE-2021-21364

Disclosure Date: March 11, 2021 (last updated February 22, 2025)
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between all local users. When files/directories are created, the default `umask` settings for the process are respected. As a result, by default, most processes/apis will create files/directories with the permissions `-rw-r--r--` and `drwxr-xr-x` respectively, unless an API that explicitly sets safe file permissions is used. Because this vulnerability impacts generated code, the generated code will remain vulnerable until fixed manually! This vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21363.