|
196411
|
7.2 |
HIGH
Network
|
multitech
|
conduit_mtcdt-lvw2-246a_firmware
|
MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metac…
|
CWE-78
OS Command
|
CVE-2020-7594
|
2024-11-21 14:37 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196412
|
4.8 |
MEDIUM
Network
|
sonoff
|
th10_firmware th16_firmware
|
Sonoff TH 10 and 16 devices with firmware 6.6.0.21 allows XSS via the Friendly Name 1 field (after a successful login with the Web Admin Password).
|
CWE-79
Cross-site Scripting
|
CVE-2020-7470
|
2024-11-21 14:37 |
2020-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196413
|
7.5 |
HIGH
Network
|
mozilla
|
bleach
|
bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2020-6817
|
2024-11-21 14:36 |
2023-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196414
|
9.8 |
CRITICAL
Network
|
seagate
|
stcg2000300_firmware stcg3000300_firmware stcg4000300_firmware
|
The web-management application on Seagate Central NAS STCG2000300, STCG3000300, and STCG4000300 devices allows OS command injection via mv_backend_launch in cirrus/application/helpers/mv_backend_help…
|
CWE-78
OS Command
|
CVE-2020-6627
|
2024-11-21 14:36 |
2022-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196415
|
8.6 |
HIGH
Network
|
rockwellautomation
|
armor_compact_guardlogix_5370_firmware compact_guardlogix_5370_firmware compactlogix_5370_l1_firmware compactlogix_5370_l2_firmware compactlogix_5370_l3_firmware controllogix_5570_firm…
|
The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creat…
|
CWE-20
Improper Input Validation
|
CVE-2020-6998
|
2024-11-21 14:36 |
2022-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196416
|
7.8 |
HIGH
Local
|
hp
|
support_assistant
|
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
|
NVD-CWE-noinfo
|
CVE-2020-6922
|
2024-11-21 14:36 |
2022-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196417
|
7.8 |
HIGH
Local
|
hp
|
support_assistant
|
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
|
NVD-CWE-noinfo
|
CVE-2020-6921
|
2024-11-21 14:36 |
2022-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196418
|
5.5 |
MEDIUM
Local
|
hp
|
support_assistant
|
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
|
NVD-CWE-noinfo
|
CVE-2020-6920
|
2024-11-21 14:36 |
2022-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196419
|
7.8 |
HIGH
Local
|
hp
|
support_assistant
|
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
|
NVD-CWE-noinfo
|
CVE-2020-6919
|
2024-11-21 14:36 |
2022-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196420
|
7.8 |
HIGH
Local
|
hp
|
support_assistant
|
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
|
NVD-CWE-noinfo
|
CVE-2020-6918
|
2024-11-21 14:36 |
2022-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|