|
197221
|
8.1 |
HIGH
Network
|
siemens
|
opcenter_execution_core
|
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2). Through the use of several vulnerable fields of the application, an a…
|
CWE-89
SQL Injection
|
CVE-2020-7577
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197222
|
6.7 |
MEDIUM
Local
|
siemens
|
simatic_pcs_neo opcenter_execution_discrete opcenter_execution_foundation opcenter_execution_process opcenter_intelligence opcenter_quality opcenter_rd\&l simatic_step_7 s…
|
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcent…
|
-
|
CVE-2020-7581
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197223
|
5.4 |
MEDIUM
Network
|
siemens
|
opcenter_execution_core
|
A vulnerability has been identified in Camstar Enterprise Platform (All versions), Opcenter Execution Core (All versions < V8.2), Opcenter Execution Core (V8.2). An authenticated user with the abilit…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7576
|
2024-11-21 14:37 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197224
|
9.8 |
CRITICAL
Network
|
tobesoft
|
xplatform
|
XPLATFORM v9.2.260 and eariler versions contain a vulnerability that could allow remote files to be downloaded by setting the arguments to the vulnerable method. this can be leveraged for code execut…
|
NVD-CWE-noinfo
|
CVE-2020-7815
|
2024-11-21 14:37 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197225
|
9.8 |
CRITICAL
Network
|
raonwiz
|
raon_k_upload
|
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-ex…
|
CWE-20
Improper Input Validation
|
CVE-2020-7814
|
2024-11-21 14:37 |
2020-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197226
|
5.3 |
MEDIUM
Network
|
sockjs_project
|
sockjs
|
Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-7693
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197227
|
9.1 |
CRITICAL
Network
|
google
|
oauth_client_library_for_java
|
PKCE support is not implemented in accordance with the RFC for OAuth 2.0 for Native Apps. Without the use of PKCE, the authorization code returned by an authorization server is not enough to guarante…
|
CWE-863
Incorrect Authorization
|
CVE-2020-7692
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197228
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r362281, 11.4-STABLE before r362281, and 11.4-RELEASE before p1, long values in the user-controlled PATH environment variable cause posix_spawnp to write beyond the end …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-7458
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197229
|
8.1 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 11.3-RELEASE before p11, missing synchronization in the IPV6_2292PKTOPTIONS sock…
|
CWE-362 CWE-416 CWE-662
Race Condition Use After Free Improper Synchronization
|
CVE-2020-7457
|
2024-11-21 14:37 |
2020-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197230
|
6.1 |
MEDIUM
Network
|
parall
|
jspdf
|
In all versions of the package jspdf, it is possible to use <<script>script> in order to go over the filtering regex.
|
CWE-79
Cross-site Scripting
|
CVE-2020-7691
|
2024-11-21 14:37 |
2020-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|