|
196471
|
9.8 |
CRITICAL
Network
|
objectcomputing
|
micronaut
|
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed …
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-7611
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196472
|
9.8 |
CRITICAL
Network
|
mongodb
|
bson
|
All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialize…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7610
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196473
|
6.5 |
MEDIUM
Adjacent
|
gradle
|
plugin_publishing
|
All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publishes a Gradle plugin while running Gradle with th…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-7599
|
2024-11-21 14:37 |
2020-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196474
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_…
|
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scriptin…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7482
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196475
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_…
|
A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could enable a successful Cross-site Scripti…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7481
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196476
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
andover_continuum_9680_firmware andover_continuum_5740_firmware andover_continuum_5720_firmware andover_continuum_bcx4040_firmware andover_continuum_bcx9640_firmware andover_continuum_…
|
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewab…
|
CWE-94
Code Injection
|
CVE-2020-7480
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196477
|
7.8 |
HIGH
Local
|
schneider-electric
|
interactive_graphical_scada_system
|
A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that ot…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-7479
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196478
|
7.5 |
HIGH
Network
|
schneider-electric
|
interactive_graphical_scada_system
|
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read…
|
CWE-22
Path Traversal
|
CVE-2020-7478
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196479
|
7.8 |
HIGH
Local
|
schneider-electric
|
ulti_zigbee_installation_toolkit
|
A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search pa…
|
CWE-426
Untrusted Search Path
|
CVE-2020-7476
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196480
|
7.5 |
HIGH
Network
|
schneider-electric
|
140noe77101_firmware 140noe77111_firmware tsxh5744m_firmware tsxh5724m_firmware tsxp576634m_firmware tsxp57554m_firmware tsxp575634m_firmware tsxp57454m_firmware tsxp574634m_f…
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in Quantum Ethernet Network module 140NOE771x1 (Versions 7.0 and prior), Quantum processors with integrated Ethern…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2020-7477
|
2024-11-21 14:37 |
2020-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|