|
210131
|
8.8 |
HIGH
Network
|
pepperl-fuchs
|
io-link_master_4-eip_firmware io-link_master_8-eip_firmware io-link_master_8-eip-l_firmware io-link_master_dr-8-eip_firmware io-link_master_dr-8-eip-p_firmware io-link_master_dr-8-eip-…
|
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
|
CWE-352
Origin Validation Error
|
CVE-2020-12511
|
2024-11-21 13:59 |
2021-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210132
|
4.3 |
MEDIUM
Network
|
apache
|
guacamole
|
Apache Guacamole 1.2.0 and earlier do not consistently restrict access to connection history based on user visibility. If multiple users share access to the same connection, those users may be able t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-11997
|
2024-11-21 13:59 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210133
|
9.8 |
CRITICAL
Network
|
apache
|
dubbo
|
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserializati…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11995
|
2024-11-21 13:59 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210134
|
9.8 |
CRITICAL
Network
|
apache
|
dolphinscheduler
|
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
|
NVD-CWE-noinfo
|
CVE-2020-11974
|
2024-11-21 13:59 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210135
|
6.5 |
MEDIUM
Adjacent
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system ser…
|
CWE-20
Improper Input Validation
|
CVE-2020-12521
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210136
|
9.8 |
CRITICAL
Network
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
|
CWE-269
Improper Privilege Management
|
CVE-2020-12519
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210137
|
5.5 |
MEDIUM
Local
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
|
CWE-200
Information Exposure
|
CVE-2020-12518
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210138
|
9.0 |
CRITICAL
Network
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12517
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210139
|
9.1 |
CRITICAL
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware fl_mguard_rs4004_tx\/dtx_firmware fl_mguard_rs4004_tx\/dtx_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mg…
|
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the L…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-12523
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210140
|
9.8 |
CRITICAL
Network
|
wago
|
pfc_100_firmware pfc_200_firmware touch_panel_600_standard_firmware touch_panel_600_advanced_firmware touch_panel_600_marine_firmware
|
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/x…
|
CWE-78
OS Command
|
CVE-2020-12522
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|