CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
A CSRF issue in phpMyAdmin 4.9.0.1 allows deletion of any server in the Setup page.
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
Clever_dog_smart_camera_panorama_dog-2w_firmware, Clever_dog_smart_camera_panorama_dog-2w, Clever_dog_smart_camera_plus_dog-2w-v4_firmware, Clever_dog_smart_camera_plus_dog-2w-v4
2019-06-27
N/A
9.8 CRITICAL
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the network can login remotely to the camera and gain root access. The device ships with a hardcoded 12345678 password for the root account, accessible from a TELNET login prompt.
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'.
Clever_dog_smart_camera_panorama_dog-2w_firmware, Clever_dog_smart_camera_panorama_dog-2w, Clever_dog_smart_camera_plus_dog-2w-v4_firmware, Clever_dog_smart_camera_plus_dog-2w-v4
2021-07-21
N/A
5.5 MEDIUM
On Shenzhen Cylan Clever Dog Smart Camera DOG-2W and DOG-2W-V4 devices, an attacker on the local network has unauthenticated access to the internal SD card via the HTTP service on port 8000. The HTTP web server on the camera allows anyone to view or download the video archive recorded and saved on the external memory card attached to the device.
Quest KACE Systems Management Appliance Server Center version 9.1.317 is vulnerable to SQL injection. The affected file is software_library.php and affected parameters are order[0][column] and order[0][dir].
A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
