|
209921
|
8.2 |
HIGH
Adjacent
|
rockwellautomation
|
eds_subsystem rsnetworx rslinx rslinx_enterprise studio_5000_logix_designer
|
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, R…
|
CWE-89
SQL Injection
|
CVE-2020-12034
|
2024-11-21 13:59 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209922
|
5.5 |
MEDIUM
Local
|
rockwellautomation
|
eds_subsystem rsnetworx rslinx rslinx_enterprise studio_5000_logix_designer
|
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, R…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12038
|
2024-11-21 13:59 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209923
|
7.5 |
HIGH
Network
|
powerdns fedoraproject debian opensuse
|
recursor fedora debian_linux leap backports_sle
|
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allow…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-12244
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209924
|
5.4 |
MEDIUM
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to reflected XSS. The devicemgmnt.php file improperly validates user input. An attacker can exploit this by crafting arbitrary JavaScript in the deviceId GET parameter to …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12256
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209925
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to remote code execution due to improper validation in the file upload functionality. vendor.crud.php accepts a file upload by checking content-type without considering th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12255
|
2024-11-21 13:59 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209926
|
9.1 |
CRITICAL
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerab…
|
CWE-384
Session Fixation
|
CVE-2020-12258
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209927
|
8.8 |
HIGH
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to cross-site request forgery (CSRF) because it lacks implementation of CSRF protection such as a CSRF token. An attacker can leverage this vulnerability by creating a for…
|
CWE-352
Origin Validation Error
|
CVE-2020-12257
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209928
|
5.4 |
MEDIUM
Network
|
rconfig
|
rconfig
|
rConfig 3.9.4 is vulnerable to reflected XSS. The configDevice.php file improperly validates user input. An attacker can exploit this vulnerability by crafting arbitrary JavaScript in the rid GET par…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12259
|
2024-11-21 13:59 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209929
|
9.8 |
CRITICAL
Network
|
vandyke
|
securecrt
|
SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-12651
|
2024-11-21 13:59 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209930
|
6.5 |
MEDIUM
Network
|
codesys
|
development_system control_for_beaglebone control_for_empc-a\/imx6 control_for_iot2000 control_for_pfc100 control_for_pfc200 control_for_plcnext control_for_raspberry_pi contr…
|
An issue was discovered in CODESYS Development System before 3.5.16.0. CODESYS WebVisu and CODESYS Remote TargetVisu are susceptible to privilege escalation.
|
NVD-CWE-noinfo
|
CVE-2020-12068
|
2024-11-21 13:59 |
2020-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|