|
196321
|
7.8 |
HIGH
Local
|
schneider-electric
|
easergy_builder
|
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker access to the authorization credentials f…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-7514
|
2024-11-21 14:37 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196322
|
7.5 |
HIGH
Network
|
schneider-electric
|
tricon_tcm_4351_firmware tricon_tcm_4352_firmware tricon_tcm_4351a_firmware tricon_tcm_4351b_firmware tricon_tcm_4352a_firmware tricon_tcm_4352b_firmware tristation_1131_firmware
|
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy debug port account in TCMs installed in Tricon system versions 10.2.0 through 10.5.3 is visible on the network and could allow inappropriate access. T…
|
NVD-CWE-noinfo
|
CVE-2020-7491
|
2024-11-21 14:37 |
2020-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196323
|
6.1 |
MEDIUM
Network
|
docsifyjs
|
docsify
|
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters after # sign) to load resources from server-side .md files. Due to lack of valid…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7680
|
2024-11-21 14:37 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196324
|
7.8 |
HIGH
Local
|
hmtalk
|
daviewindy
|
DaviewIndy 8.98.9 and earlier has a Heap-based overflow vulnerability, triggered when the user opens a malformed PDF file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7818
|
2024-11-21 14:37 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196325
|
9.8 |
CRITICAL
Network
|
eyesurfer
|
bflyinstallerx.ocx
|
EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting the arguments to the vulnerable method. This can be leverag…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2020-7826
|
2024-11-21 14:37 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196326
|
9.8 |
CRITICAL
Network
|
tobesoft
|
miplatform
|
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending …
|
CWE-78
OS Command
|
CVE-2020-7825
|
2024-11-21 14:37 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196327
|
5.3 |
MEDIUM
Network
|
react-native-fast-image_project
|
react-native-fast-image
|
This affects all versions of package react-native-fast-image. When an image with source={{uri: "...", headers: { host: "somehost.com", authorization: "..." }} is loaded, all other subsequent images w…
|
CWE-200
Information Exposure
|
CVE-2020-7696
|
2024-11-21 14:37 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196328
|
9.8 |
CRITICAL
Network
|
rollup-plugin-serve_project
|
rollup-plugin-serve
|
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
|
CWE-22
Path Traversal
|
CVE-2020-7684
|
2024-11-21 14:37 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196329
|
4.3 |
MEDIUM
Network
|
mcafee
|
web_gateway
|
Inappropriate Encoding for output context vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows a remote attacker to cause MWG to return an ambiguous redirect response via getting a user to…
|
CWE-838
Inappropriate Encoding for Output Context
|
CVE-2020-7292
|
2024-11-21 14:37 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196330
|
9.8 |
CRITICAL
Network
|
siemens
|
logo\!_8_bm_firmware
|
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.01), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.02). A buffer…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-7593
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|