Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-52150 | Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Cross-Site Request Forgery (CSRF) vulnerability in Ovation S.R.L. Dynamic Content for Elementor.This issue affects Dynamic Content for Elementor: from n/a before 2.12.5. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2022-29594 | eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2021-3327 | Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2020-29001 | An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devi An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The vulnerability exists because a static username and password are compiled into the ppsapp RESTful application. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2020-8591 +1 in the same advisory: …8592 | eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2018-15885 | Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for d Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities or purpose. This makes it easier for adversaries to detect the covert operation. Specifically, the product uses a compression technique to prevent the identification of certain libraries in the software by obfuscation. The software relies on a TLS callback and an additional executable file to enable these libraries and their access to certain websites. The unpacked software can be exploited by several different types of documented techniques. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — |