|
196651
|
5.3 |
MEDIUM
Network
|
siemens
|
simatic_pcs_neo opcenter_execution_discrete opcenter_execution_foundation opcenter_execution_process opcenter_intelligence opcenter_quality opcenter_rd\&l simatic_step_7 s…
|
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcent…
|
-
|
CVE-2020-7588
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196652
|
8.2 |
HIGH
Network
|
siemens
|
opcenter_execution_discrete opcenter_execution_foundation opcenter_execution_process opcenter_quality opcenter_rd\&l simatic_step_7 simatic_notifier_server soft_starter_es
|
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcent…
|
-
|
CVE-2020-7587
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196653
|
8.1 |
HIGH
Network
|
siemens
|
opcenter_execution_core
|
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Authenticated users could have access to resources they normally woul…
|
CWE-269
Improper Privilege Management
|
CVE-2020-7578
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196654
|
8.1 |
HIGH
Network
|
siemens
|
opcenter_execution_core
|
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Through the use of several vulnerable fields of the application, an a…
|
CWE-89
SQL Injection
|
CVE-2020-7577
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196655
|
6.7 |
MEDIUM
Local
|
siemens
|
simatic_pcs_neo opcenter_execution_discrete opcenter_execution_foundation opcenter_execution_process opcenter_intelligence opcenter_quality opcenter_rd\&l simatic_step_7 s…
|
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcent…
|
-
|
CVE-2020-7581
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196656
|
5.4 |
MEDIUM
Network
|
siemens
|
opcenter_execution_core
|
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2), Opcenter Execution Core (V8.2). An authenticated user with the abilit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7576
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196657
|
9.8 |
CRITICAL
Network
|
tobesoft
|
xplatform
|
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execut…
|
NVD-CWE-noinfo
|
CVE-2020-7815
|
2024-11-21 14:37 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196658
|
9.8 |
CRITICAL
Network
|
raonwiz
|
raon_k_upload
|
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-ex…
|
CWE-20
Improper Input Validation
|
CVE-2020-7814
|
2024-11-21 14:37 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196659
|
5.3 |
MEDIUM
Network
|
sockjs_project
|
sockjs
|
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-7693
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196660
|
9.1 |
CRITICAL
Network
|
google
|
oauth_client_library_for_java
|
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarante…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7692
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|