|
210511
|
5.5 |
MEDIUM
Local
|
intel
|
jhl6240_thunderbolt_3_firmware jhl6340_thunderbolt_3_firmware jhl6540_thunderbolt_3_firmware jhl7040_thunderbolt_3_retimer_firmware jhl7340_thunderbolt_3_firmware jhl7440_thunderbolt_3…
|
Protection mechanism failure in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.
|
NVD-CWE-Other
|
CVE-2020-12288
|
2024-11-21 13:59 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210512
|
9.1 |
CRITICAL
Network
|
mozilla
|
nss
|
A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly di…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12403
|
2024-11-21 13:59 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210513
|
9.8 |
CRITICAL
Network
|
nitrokey
|
fido_u2f_firmware
|
An issue was discovered in Nitrokey FIDO U2F firmware through 1.1. Communication between the microcontroller and the secure element transmits credentials in plain. This allows an adversary to eavesdr…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-12061
|
2024-11-21 13:59 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210514
|
5.3 |
MEDIUM
Network
|
beckhoff
|
ipc_diagnostics_ua_server tf6100 twincat_opc_ua_server
|
TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attack…
|
CWE-20
Improper Input Validation
|
CVE-2020-12526
|
2024-11-21 13:59 |
2021-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210515
|
6.1 |
MEDIUM
Network
|
vivo
|
appstore
|
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.
|
CWE-601
Open Redirect
|
CVE-2020-12483
|
2024-11-21 13:59 |
2021-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210516
|
6.1 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. There is an XSS issue in the redirect.php allowing an attacker to inject code via a g…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12530
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210517
|
5.3 |
MEDIUM
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2 There is a SSRF in the LDAP access check, allowing an attacker to scan for open ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-12529
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210518
|
7.7 |
HIGH
Network
|
mbconnectline
|
mbconnect24 mymbconnect24
|
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2. Improper use of access validation allows a logged in user to kill web2go sessions in …
|
CWE-269
Improper Privilege Management
|
CVE-2020-12528
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210519
|
6.5 |
MEDIUM
Network
|
mbconnectline helmholz
|
mbconnect24 mymbconnect24 myrex24.virtual myrex24
|
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. Improper access validation allows a logged in user to s…
|
-
|
CVE-2020-12527
|
2024-11-21 13:59 |
2021-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210520
|
8.2 |
HIGH
Network
|
apache fedoraproject
|
xmlgraphics_commons fedora
|
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2020-11988
|
2024-11-21 13:59 |
2021-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|