|
209791
|
6.5 |
MEDIUM
Network
|
college_management_system_project
|
college_management_system
|
A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, facult…
|
CWE-352
Origin Validation Error
|
CVE-2020-25408
|
2024-11-21 14:17 |
2021-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209792
|
7.5 |
HIGH
Network
|
siemens
|
simatic_net_cp_343-1_advanced_firmware simatic_net_cp_343-1_lean_firmware simatic_net_cp_343-1_standard_firmware
|
A vulnerability has been identified in SIMATIC NET CP 343-1 Advanced (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Lean (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Sta…
|
-
|
CVE-2020-25242
|
2024-11-21 14:17 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209793
|
8.4 |
HIGH
Local
|
siemens
|
logo\!_soft_comfort
|
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). The software insecurely loads libraries which makes it vulnerable to DLL hijacking.
Successful exploitation by a local…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-25244
|
2024-11-21 14:17 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209794
|
5.1 |
MEDIUM
Local
|
siemens
|
logo\!_soft_comfort
|
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file
to the affected software. Chain…
|
-
|
CVE-2020-25243
|
2024-11-21 14:17 |
2021-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209795
|
9.8 |
CRITICAL
Network
|
grandstream
|
grp2612_firmware grp2612p_firmware grp2612w_firmware grp2613_firmware grp2614_firmware grp2615_firmware grp2616_firmware
|
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-25218
|
2024-11-21 14:17 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209796
|
7.2 |
HIGH
Network
|
grandstream
|
grp2612_firmware grp2612p_firmware grp2612w_firmware grp2613_firmware grp2614_firmware grp2615_firmware grp2616_firmware
|
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
|
CWE-77
Command Injection
|
CVE-2020-25217
|
2024-11-21 14:17 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209797
|
8.6 |
HIGH
Network
|
squid-cache debian fedoraproject netapp
|
squid debian_linux fedora cloud_manager
|
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbi…
|
CWE-20 CWE-444
Improper Input Validation HTTP Request Smuggling
|
CVE-2020-25097
|
2024-11-21 14:17 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209798
|
7.5 |
HIGH
Network
|
siemens
|
simatic_mv440_sr_firmware simatic_mv440_hr_firmware simatic_mv440_ur_firmware simatic_mv420_sr-b_firmware simatic_mv420_sr-p_firmware simatic_mv420_sr-b_body_firmware simatic_mv420_…
|
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-25241
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209799
|
8.8 |
HIGH
Network
|
siemens
|
sinema_remote_connect_server
|
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integr…
|
-
|
CVE-2020-25240
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209800
|
8.8 |
HIGH
Network
|
siemens
|
sinema_remote_connect_server
|
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the…
|
-
|
CVE-2020-25239
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|