• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-20477
2022-01-01
N/A
9.8 CRITICAL
PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an incomplete fix for CVE-2017-18342.
CVE-2019-20474
2022-01-01
N/A
4.3 MEDIUM
An issue was discovered in Zoho ManageEngine Remote Access Plus 10.0.447. The service to test the mail-server configuration suffers from an authorization issue allowing a user with the Guest role (read-only access) to use and abuse it. One of the abuses allows performing network and port scan operations of the localhost or the hosts on the same network segment, aka SSRF.
CVE-2019-20473
Q90 Junior Gps Horloge Firmware, Tk-star
Q90_junior_gps_horloge_firmware, Q90_junior_gps_horloge
2021-02-05
N/A
6.8 MEDIUM
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. Any SIM card used with the device cannot have a PIN configured. If a PIN is configured, the device simply produces a "Remove PIN and restart!" message, and cannot be used. This makes it easier for an attacker to use the SIM card by stealing the device.
CVE-2019-20471
Q90 Junior Gps Horloge Firmware, Tk-star
Q90_junior_gps_horloge_firmware, Q90_junior_gps_horloge
2021-02-05
N/A
7.8 HIGH
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the device at initial setup, a default password is used (123456) for administrative purposes. There is no prompt to change this password. Note that this password can be used in combination with CVE-2019-20470.
CVE-2019-20470
Q90 Junior Gps Horloge Firmware, Tk-star
Q90_junior_gps_horloge_firmware, Q90_junior_gps_horloge
2021-07-21
N/A
7.5 HIGH
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs actions based on certain SMS commands. This can be used to set up a voice communication channel from the watch to any telephone number, initiated by sending a specific SMS and using the default password, e.g., pw,,call, triggers an outbound call from the watch. The password is sometimes available because of CVE-2019-20471.
CVE-2019-2047
2021-07-21
N/A
9.8 CRITICAL
In UpdateLoadElement of ic.cc, there is a possible out-of-bounds write due to type confusion. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9 Android ID: A-117607414
CVE-2019-20468
Q90 Junior Gps Horloge Firmware, Tk-star
Q90_junior_gps_horloge_firmware, Q90_junior_gps_horloge
2021-02-05
N/A
9.8 CRITICAL
An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, and READ_CONTACTS.
CVE-2019-20467
Sannce, Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware
Smart_hd_wifi_security_camera_ean_2_950004_595317_firmware, Smart_hd_wifi_security_camera_ean_2_950004_595317
2021-08-04
N/A
9.8 CRITICAL
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. The device by default has a TELNET interface available (which is not advertised or functionally used, but is nevertheless available). Two backdoor accounts (root and default) exist that can be used on this interface. The usernames and passwords of the backdoor accounts are the same on all devices. Attackers can use these backdoor accounts to obtain access and execute code as root within the device.
CVE-2019-20466
Sannce, Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware
Smart_hd_wifi_security_camera_ean_2_950004_595317_firmware, Smart_hd_wifi_security_camera_ean_2_950004_595317
2021-04-08
N/A
7.8 HIGH
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. A local attacker with the "default" account is capable of reading the /etc/passwd file, which contains a weakly hashed root password. By taking this hash and cracking it, the attacker can obtain root rights on the device.
CVE-2019-20465
Sannce, Smart Hd Wifi Security Camera Ean 2 950004 595317 Firmware
Smart_hd_wifi_security_camera_ean_2_950004_595317_firmware, Smart_hd_wifi_security_camera_ean_2_950004_595317
2021-04-08
N/A
7.5 HIGH
An issue was discovered on Sannce Smart HD Wifi Security Camera EAN 2 950004 595317 devices. It is possible (using TELNET without a password) to control the camera's pan/zoom/tilt functionality.
« Previous 1 … 5,707 5,708 5,709 5,710 5,711 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE