CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote code execution because of javax.faces.ViewState Java deserialization.
Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.
The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).
The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'VBScript Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1214, CVE-2020-1215, CVE-2020-1216, CVE-2020-1230, CVE-2020-1260.
The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.
DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2021-07-21
N/A
7.5 HIGH
An information disclosure vulnerability in the /cgi-bin/ExportAllSettings.sh endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to leak router settings, including cleartext login details, DNS settings, and other sensitive information without authentication.
Wl-wn575a3_firmware, Wl-wn575a3, Wl-wn530hg4_firmware, Wl-wn530hg4, Wl-wn579g3_firmware, Wl-wn579g3, Wn530hg4_firmware, Wn530hg4, Wn531g3_firmware, Wn531g3
2020-10-08
N/A
9.8 CRITICAL
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.
