|
196721
|
8.8 |
HIGH
Network
|
cloudfoundry
|
cf-deployment user_account_and_authentication
|
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity pr…
|
CWE-352
Origin Validation Error
|
CVE-2020-5402
|
2024-11-21 14:34 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196722
|
5.3 |
MEDIUM
Network
|
cloudfoundry
|
routing_release
|
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients try…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-5401
|
2024-11-21 14:34 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196723
|
6.5 |
MEDIUM
Network
|
cloudfoundry
|
cf-deployment capi-release
|
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the j…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-5400
|
2024-11-21 14:34 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196724
|
8.8 |
HIGH
Adjacent
|
nec
|
aterm_wg2600hs_firmware aterm_wf1200c_firmware aterm_wg1200cr_firmware
|
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment t…
|
CWE-78
OS Command
|
CVE-2020-5524
|
2024-11-21 14:34 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196725
|
8.0 |
HIGH
Adjacent
|
nec
|
aterm_wg2600hs_firmware
|
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2020-5534
|
2024-11-21 14:34 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196726
|
6.1 |
MEDIUM
Network
|
nec
|
aterm_wg2600hs_firmware
|
Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2020-5533
|
2024-11-21 14:34 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196727
|
8.0 |
HIGH
Adjacent
|
nec
|
aterm_wg2600hs_firmware aterm_wf1200c_firmware aterm_wg1200cr_firmware
|
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same net…
|
CWE-78
OS Command
|
CVE-2020-5525
|
2024-11-21 14:34 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196728
|
8.8 |
HIGH
Network
|
realestateconnected
|
easy_property_listings
|
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
|
CWE-352
Origin Validation Error
|
CVE-2020-5530
|
2024-11-21 14:34 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196729
|
9.8 |
CRITICAL
Network
|
mitsubishielectric
|
mi5122-vw_firmware q24dhccpu-v_firmware q24dhccpu-vg_firmware r12ccpu-v_firmware rd55up06-v_firmware
|
Mitsubishi Electric MELSEC C Controller Module and MELIPC Series MI5000 MELSEC-Q Series C Controller Module(Q24DHCCPU-V, Q24DHCCPU-VG User Ethernet port (CH1, CH2): First 5 digits of serial number 21…
|
NVD-CWE-noinfo
|
CVE-2020-5531
|
2024-11-21 14:34 |
2020-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196730
|
4.3 |
MEDIUM
Network
|
extrun
|
ilbo
|
ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images whic…
|
CWE-287
Improper Authentication
|
CVE-2020-5532
|
2024-11-21 14:34 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|