|
197091
|
8.2 |
HIGH
Network
|
arachnys
|
cabot
|
All versions of package cabot are vulnerable to Cross-site Scripting (XSS) via the Endpoint column.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7734
|
2024-11-21 14:37 |
2020-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197092
|
6.5 |
MEDIUM
Local
|
rapid7
|
appspider
|
In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This wo…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-7358
|
2024-11-21 14:37 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197093
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_x70_security_administrator
|
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-7532
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197094
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever R…
|
NVD-CWE-noinfo
|
CVE-2020-7531
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197095
|
8.8 |
HIGH
Network
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
|
NVD-CWE-Other
|
CVE-2020-7530
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197096
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place …
|
-
|
CVE-2020-7529
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197097
|
7.8 |
HIGH
Local
|
schneider-electric
|
scadapack_7x_remote_connect
|
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ…
|
-
|
CVE-2020-7528
|
2024-11-21 14:37 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197098
|
7.5 |
HIGH
Network
|
ua-parser-js_project oracle
|
ua-parser-js communications_cloud_native_core_network_function_cloud_native_environment
|
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-7733
|
2024-11-21 14:37 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197099
|
5.7 |
MEDIUM
Adjacent
|
mcafee
|
web_gateway
|
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user inter…
|
CWE-287
Improper Authentication
|
CVE-2020-7297
|
2024-11-21 14:37 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197100
|
5.7 |
MEDIUM
Adjacent
|
mcafee
|
web_gateway
|
Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user …
|
CWE-287
Improper Authentication
|
CVE-2020-7296
|
2024-11-21 14:37 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|