|
199861
|
9.8 |
CRITICAL
Network
|
amazon
|
aws_shared_configuration_file_loader aws_sdk_for_javascipt
|
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadS…
|
NVD-CWE-noinfo
|
CVE-2020-28472
|
2024-11-21 14:22 |
2021-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199862
|
6.1 |
MEDIUM
Network
|
scully
|
scully
|
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-28470
|
2024-11-21 14:22 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199863
|
6.8 |
MEDIUM
Network
|
bottlepy debian
|
bottle debian_linux
|
The package bottle from 0 and before 0.12.19 are vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), …
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-28473
|
2024-11-21 14:22 |
2021-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199864
|
5.5 |
MEDIUM
Local
|
siemens
|
opcenter_execution_core
|
A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an information leakage vulnerability in the handling of web client sess…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-28390
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199865
|
7.8 |
HIGH
Local
|
siemens
|
solid_edge
|
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28386
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199866
|
7.8 |
HIGH
Local
|
siemens
|
solid_edge
|
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28384
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199867
|
7.8 |
HIGH
Local
|
siemens
|
solid_edge
|
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28382
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199868
|
7.8 |
HIGH
Local
|
siemens
|
solid_edge
|
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-28381
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199869
|
8.1 |
HIGH
Network
|
linux fedoraproject debian
|
linux_kernel fedora debian_linux
|
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via direct…
|
CWE-22
Path Traversal
|
CVE-2020-28374
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199870
|
5.9 |
MEDIUM
Network
|
siemens
|
scalance_xr324-12m_firmware scalance_xr324-12m_ts_firmware scalance_xr324-4m_eec_firmware scalance_xr324-4m_poe_firmware scalance_xr324-4m_poe_ts_firmware scalance_xr324wg_firmware …
|
A vulnerability has been identified in SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.0). Devices do n…
|
-
|
CVE-2020-28395
|
2024-11-21 14:22 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|