CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
There is Stored XSS in Verodin Director 3.5.3.0 and earlier via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages.
LocaleLowercase in MagickCore/locale.c in ImageMagick before 7.0.8-32 allows out-of-bounds access, leading to a SIGSEGV.
750-830_firmware, 750-830, 750-849_firmware, 750-849, 750-871_firmware, 750-871, 750-872_firmware, 750-872, 750-873_firmware, 750-873
2020-10-01
N/A
9.8 CRITICAL
The Web-GUI on WAGO Series 750-88x (750-330, 750-352, 750-829, 750-831, 750-852, 750-880, 750-881, 750-882, 750-884, 750-885, 750-889) and Series 750-87x (750-830, 750-849, 750-871, 750-872, 750-873) devices has undocumented service access.
2020-08-24
N/A
7.5 HIGH
Incorrect access control in the RTSP stream and web portal on all IP cameras based on Hisilicon Hi3510 firmware (until Webware version V1.0.1) allows attackers to view an RTSP stream by connecting to the stream with hidden credentials (guest or user) that are neither displayed nor configurable in the camera's CamHi or keye mobile management application. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.
2020-08-24
N/A
8.8 HIGH
Insecure permissions in the Web management portal on all IP cameras based on Hisilicon Hi3510 firmware allow authenticated attackers to receive a network's cleartext WiFi credentials via a specific HTTP request. This affects certain devices labeled as HI3510, HI3518, LOOSAFE, LEVCOECAM, Sywstoda, BESDER, WUSONGLUSAN, GADINAN, Unitoptek, ESCAM, etc.
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1073.
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \.AsusTP device, leading to a DoS or potentially privilege escalation via a crafted DeviceIoControl call.
S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
Sandisk_x600_sd9tb8w-128g_firmware, Sandisk_x600_sd9tb8w-128g, Sandisk_x600_sd9tb8w-256g_firmware, Sandisk_x600_sd9tb8w-256g, Sandisk_x600_sd9tb8w-512g_firmware, Sandisk_x600_sd9tb8w-512g, Sandisk_x600_sd9tb8w-1t00_firmware, Sandisk_x600_sd9tb8w-1t00, Sandisk_x600_sd9tb8w-2t00_firmware, Sandisk_x600_sd9tb8w-2t00
2020-03-13
N/A
6.3 MEDIUM
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.
