|
210231
|
8.8 |
HIGH
Network
|
openrobotics
|
robot_operating_system
|
Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-10289
|
2024-11-21 13:55 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210232
|
9.9 |
CRITICAL
Network
|
redhat
|
openstack_platform
|
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be d…
|
NVD-CWE-noinfo
|
CVE-2020-10731
|
2024-11-21 13:55 |
2020-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210233
|
8.2 |
HIGH
Local
|
gnu debian opensuse vmware
|
grub2 debian_linux leap photon_os
|
A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. …
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-10713
|
2024-11-21 13:55 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210234
|
5.4 |
MEDIUM
Network
|
osisoft
|
pi_vision
|
An authenticated remote attacker could use specially crafted URLs to send a victim using PI Vision 2019 mobile to a vulnerable web page due to a known issue in a third-party component.
|
CWE-79
Cross-site Scripting
|
CVE-2020-10643
|
2024-11-21 13:55 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210235
|
7.5 |
HIGH
Network
|
grundfos
|
cim_500
|
Grundfos CIM 500 v06.16.00 stores plaintext credentials, which may allow sensitive information to be read or allow modification to system settings by someone with access to the device.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-10609
|
2024-11-21 13:55 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210236
|
4.8 |
MEDIUM
Network
|
osisoft
|
pi_vision
|
In OSIsoft PI System multiple products and versions, an authenticated remote attacker with write access to PI Vision databases could inject code into a display. Unauthorized information disclosure, d…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10614
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210237
|
7.5 |
HIGH
Network
|
osisoft
|
pi_data_archive
|
In OSIsoft PI System multiple products and versions, a remote, unauthenticated attacker could crash PI Network Manager service through specially crafted requests. This can result in blocking connecti…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-10604
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210238
|
7.8 |
HIGH
Local
|
osisoft
|
pi_buffer_subsystem pi_api pi_connector pi_connector_relay pi_interface_configuration_utility pi_integrator pi_data_collection_manager pi_data_archive pi_to_ocs
|
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at W…
|
CWE-426
Untrusted Search Path
|
CVE-2020-10610
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210239
|
7.8 |
HIGH
Local
|
osisoft
|
pi_buffer_subsystem pi_api pi_connector pi_connector_relay pi_interface_configuration_utility pi_integrator pi_data_collection_manager pi_data_archive pi_to_ocs
|
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-10608
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210240
|
5.3 |
MEDIUM
Network
|
pi
|
data_archive
|
In OSIsoft PI System multiple products and versions, an authenticated remote attacker could crash PI Network Manager due to a race condition. This can result in blocking connections and queries to PI…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10602
|
2024-11-21 13:55 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|