|
210501
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users
|
NVD-CWE-noinfo
|
CVE-2020-10622
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210502
|
5.5 |
MEDIUM
Local
|
lcds
|
laquis_scada
|
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.
|
CWE-200
Information Exposure
|
CVE-2020-10618
|
2024-11-21 13:55 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210503
|
9.8 |
CRITICAL
Network
|
dom4j_project oracle opensuse netapp canonical
|
dom4j insurance_policy_administration_j2ee insurance_rules_palette retail_integration_bus webcenter_portal utilities_framework flexcube_core_banking business_process_management_s…
|
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing ho…
|
CWE-611
XXE
|
CVE-2020-10683
|
2024-11-21 13:55 |
2020-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210504
|
5.2 |
MEDIUM
Local
|
redhat
|
ansible_engine ansible_tower
|
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is cr…
|
CWE-22
Path Traversal
|
CVE-2020-10691
|
2024-11-21 13:55 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210505
|
7.5 |
HIGH
Network
|
json_project fedoraproject opensuse debian apple
|
json fedora leap debian_linux macos
|
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, …
|
CWE-20
Improper Input Validation
|
CVE-2020-10663
|
2024-11-21 13:55 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210506
|
7.5 |
HIGH
Network
|
inductiveautomation
|
ignition_gateway
|
An unprotected logging route may allow an attacker to write endless log statements into the database without space limits or authentication. This results in consuming the entire available hard-disk s…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-10641
|
2024-11-21 13:55 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210507
|
7.5 |
HIGH
Network
|
windriver
|
vxworks
|
The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-10664
|
2024-11-21 13:55 |
2020-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210508
|
8.2 |
HIGH
Network
|
redhat
|
openshift_container_platform
|
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those l…
|
-
|
CVE-2020-10712
|
2024-11-21 13:55 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210509
|
9.8 |
CRITICAL
Network
|
sysaid
|
on-premise
|
SysAid On-Premise 20.1.11, by default, allows the AJP protocol port, which is vulnerable to a GhostCat attack. Additionally, it allows unauthenticated access to upload files, which can be used to exe…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-10569
|
2024-11-21 13:55 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210510
|
9.8 |
CRITICAL
Network
|
mitel
|
mivoice_connect_client mivoice_connect
|
A weak encryption vulnerability in Mitel MiVoice Connect Client before 214.100.1214.0 could allow an unauthenticated attacker to gain access to user credentials. A successful exploit could allow an a…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-10377
|
2024-11-21 13:55 |
2020-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|