CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during [2019]. Notes: none.
CodiMD 1.3.1, when Safari is used, allows XSS via an IFRAME element with allow-top-navigation in the sandbox attribute, in conjunction with a data: URL.
2020-08-24
N/A
8.8 HIGH
cgi-bin/cmh/webcam.sh in Vera Edge Home Controller 1.7.4452 allows remote unauthenticated users to execute arbitrary OS commands via --output argument injection in the username parameter to /cgi-bin/cmh/webcam.sh.
2019-09-04
N/A
9.8 CRITICAL
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
