|
196261
|
7.5 |
HIGH
Network
|
moxa
|
iologik_2512_firmware iologik_2512-t_firmware iologik_2512-hspa_firmware iologik_2512-hspa-t_firmware iologik_2512-wl1-eu_firmware iologik_2512-wl1-eu-t_firmware iologik_2512-wl1-us…
|
In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-7003
|
2024-11-21 14:36 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196262
|
9.1 |
CRITICAL
Network
|
honeywell
|
notifier_webserver
|
In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2020-6972
|
2024-11-21 14:36 |
2020-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196263
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_services_platform
|
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsS…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-6967
|
2024-11-21 14:36 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196264
|
8.8 |
HIGH
Adjacent
|
eaton
|
ups_companion
|
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluat…
|
CWE-94
Code Injection
|
CVE-2020-6650
|
2024-11-21 14:36 |
2020-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196265
|
8.4 |
HIGH
Network
|
systech
|
nds\/5008rm_firmware nds-5000_firmware
|
Systech Corporation NDS-5000 Terminal Server, NDS/5008 (8 Port, RJ45), firmware Version 02D.30. Successful exploitation of this vulnerability could allow information disclosure, limit system availabi…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7006
|
2024-11-21 14:36 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196266
|
4.8 |
MEDIUM
Network
|
mcafee
|
network_security_manager
|
Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7258
|
2024-11-21 14:36 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196267
|
4.8 |
MEDIUM
Network
|
mcafee
|
network_security_manager
|
Cross site scripting vulnerability in McAfee Network Security Management (NSM) Prior to 9.1 update 6 Mar 2020 Update allows attackers to unspecified impact via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7256
|
2024-11-21 14:36 |
2020-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196268
|
5.5 |
MEDIUM
Local
|
deltaww
|
cncsoft_screeneditor
|
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. An out-of-bounds read overflow can be exploited when a valid user opens a specially crafted, malicious input file due to the lack…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-6976
|
2024-11-21 14:36 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196269
|
7.8 |
HIGH
Local
|
deltaww
|
cncsoft_screeneditor
|
Delta Industrial Automation CNCSoft ScreenEditor, v1.00.96 and prior. Multiple stack-based buffer overflows can be exploited when a valid user opens a specially crafted, malicious input file.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7002
|
2024-11-21 14:36 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196270
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortiweb
|
An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Disclaimer Description of a Replacem…
|
CWE-79
Cross-site Scripting
|
CVE-2020-6646
|
2024-11-21 14:36 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|