|
197411
|
7.4 |
HIGH
Adjacent
|
mitsubishielectric
|
melsec_iq-f_fx5u_cpu_firmware
|
Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on progr…
|
NVD-CWE-noinfo
|
CVE-2020-5665
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197412
|
9.8 |
CRITICAL
Network
|
soliton
|
filezen
|
Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitr…
|
CWE-22
Path Traversal
|
CVE-2020-5639
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197413
|
6.8 |
MEDIUM
Adjacent
|
necplatforms
|
aterm_sa3500g_firmware
|
Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program.
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-5637
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197414
|
6.8 |
MEDIUM
Adjacent
|
necplatforms
|
aterm_sa3500g_firmware
|
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command…
|
CWE-78
OS Command
|
CVE-2020-5636
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197415
|
8.8 |
HIGH
Adjacent
|
necplatforms
|
aterm_sa3500g_firmware
|
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command executio…
|
CWE-78
OS Command
|
CVE-2020-5635
|
2024-11-21 14:34 |
2020-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197416
|
5.3 |
MEDIUM
Network
|
f5
|
big-ip_advanced_firewall_manager
|
On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the ad…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5950
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197417
|
7.5 |
HIGH
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 14.0.0-14.0.1 and 13.1.0-13.1.3.4, certain traffic pattern sent to a virtual server configured with an FTP profile can cause the FTP channel to break.
|
NVD-CWE-noinfo
|
CVE-2020-5949
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197418
|
9.6 |
CRITICAL
Network
|
f5
|
big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system …
|
On BIG-IP versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, undisclosed endpoints in iControl REST allow for a reflected XSS attack, w…
|
CWE-79
Cross-site Scripting
|
CVE-2020-5948
|
2024-11-21 14:34 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197419
|
9.8 |
CRITICAL
Network
|
eat_spray_love_project
|
eat_spray_love
|
The Eat Spray Love mobile app for both iOS and Android contains logic that allows users to bypass authentication and retrieve or modify information that they would not normally have access to.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2020-5800
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197420
|
9.8 |
CRITICAL
Network
|
eat_spray_love_project
|
eat_spray_love
|
The Eat Spray Love mobile app for both iOS and Android contains a backdoor account that, when modified, allowed privileged access to restricted functionality and to other users' data.
|
NVD-CWE-Other
|
CVE-2020-5799
|
2024-11-21 14:34 |
2020-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|