|
199831
|
5.5 |
MEDIUM
Local
|
siemens
|
jt2go teamcenter_visualization
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when p…
|
-
|
CVE-2020-28394
|
2024-11-21 14:22 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199832
|
7.8 |
HIGH
Local
|
siemens
|
simaris_configuration
|
A vulnerability has been identified in SIMARIS configuration (All versions < V4.0.1). During installation to default target folder, incorrect permissions are configured for the application folder and…
|
-
|
CVE-2020-28392
|
2024-11-21 14:22 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199833
|
5.3 |
MEDIUM
Network
|
siemens
|
nucleus_source_code nucleus_net capital_vstar pluscontrol_1st_gen nucleus_readystart
|
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5…
|
NVD-CWE-Other
|
CVE-2020-28388
|
2024-11-21 14:22 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199834
|
8.6 |
HIGH
Network
|
decal_project
|
decal
|
This affects all versions of package decal. The vulnerability is in the extend function.
|
NVD-CWE-Other
|
CVE-2020-28450
|
2024-11-21 14:22 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199835
|
8.6 |
HIGH
Network
|
decal_project
|
decal
|
This affects all versions of package decal. The vulnerability is in the set function.
|
NVD-CWE-Other
|
CVE-2020-28449
|
2024-11-21 14:22 |
2021-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199836
|
5.4 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28001
|
2024-11-21 14:22 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199837
|
6.5 |
MEDIUM
Network
|
solarwinds
|
serv-u
|
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-27994
|
2024-11-21 14:22 |
2021-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199838
|
9.8 |
CRITICAL
Network
|
moxa
|
edr-g903_firmware edr-g903-t_firmware edr-g902_firmware edr-g902-t_firmware edr-810-2gsfp_firmware edr-810-2gsfp-t_firmware edr-810-vpn-2gsfp_firmware edr-810-vpn-2gsfp-t_firmware
|
Certain Moxa Inc products are affected by an improper restriction of operations in EDR-G903 Series Firmware Version 5.5 or lower, EDR-G902 Series Firmware Version 5.5 or lower, and EDR-810 Series Fir…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-28144
|
2024-11-21 14:22 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199839
|
6.8 |
MEDIUM
Network
|
indutny
|
elliptic
|
The package elliptic before 6.5.4 are vulnerable to Cryptographic Issues via the secp256k1 implementation in elliptic/ec/key.js. There is no check to confirm that the public key point passed into the…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-28498
|
2024-11-21 14:22 |
2021-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199840
|
7.3 |
HIGH
Network
|
totaljs
|
total.js
|
This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, l…
|
NVD-CWE-Other
|
CVE-2020-28495
|
2024-11-21 14:22 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|