|
199701
|
5.9 |
MEDIUM
Network
|
siemens
|
scalance_xr324-12m_firmware scalance_xr324-12m_ts_firmware scalance_xr324-4m_eec_firmware scalance_xr324-4m_poe_firmware scalance_xr324-4m_poe_ts_firmware scalance_xr324wg_firmware …
|
A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do n…
|
-
|
CVE-2020-28395
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199702
|
5.9 |
MEDIUM
Network
|
siemens
|
scalance_x200-4pirt_firmware scalance_x201-3pirt_firmware scalance_x202-2irt_firmware scalance_x202-2pirt_firmware scalance_x202-2pirt_siplus_net_firmware scalance_x204irt_firmware …
|
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5…
|
-
|
CVE-2020-28391
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199703
|
7.8 |
HIGH
Local
|
siemens
|
jt2go teamcenter_visualization solid_edge
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All ver…
|
-
|
CVE-2020-28383
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199704
|
5.3 |
MEDIUM
Network
|
rocket.chat
|
rocket.chat
|
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-28208
|
2024-11-21 14:22 |
2021-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199705
|
9.8 |
CRITICAL
Network
|
pwntools_project
|
pwntools
|
This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can lead to remote code ex…
|
CWE-74
Injection
|
CVE-2020-28468
|
2024-11-21 14:22 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199706
|
9.8 |
CRITICAL
Network
|
djv_project
|
djv
|
This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.
|
CWE-94
Code Injection
|
CVE-2020-28464
|
2024-11-21 14:22 |
2021-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199707
|
6.5 |
MEDIUM
Network
|
mantisbt
|
mantisbt
|
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.
|
CWE-89
SQL Injection
|
CVE-2020-28413
|
2024-11-21 14:22 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199708
|
7.5 |
HIGH
Network
|
tenda
|
ac1200_firmware
|
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2020-28095
|
2024-11-21 14:22 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199709
|
6.1 |
MEDIUM
Network
|
sapplica
|
sentrifugo
|
Sentrifugo 3.2 allows Stored Cross-Site Scripting (XSS) vulnerability by inserting a payload within the X-Forwarded-For HTTP header during the login process. When an administrator looks at logs, the …
|
CWE-79
Cross-site Scripting
|
CVE-2020-28365
|
2024-11-21 14:22 |
2020-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199710
|
9.8 |
CRITICAL
Network
|
libnested_project
|
libnested
|
Prototype pollution vulnerability in 'libnested' versions 0.0.0 through 1.5.0 allows an attacker to cause a denial of service and may lead to remote code execution.
|
NVD-CWE-Other
|
CVE-2020-28283
|
2024-11-21 14:22 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|