|
210551
|
9.8 |
CRITICAL
Network
|
apache
|
dubbo
|
A deserialization vulnerability existed in dubbo 2.7.5 and its earlier versions, which could lead to malicious code execution. Most Dubbo users use Hessian2 as the default serialization/deserializati…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-11995
|
2024-11-21 13:59 |
2021-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210552
|
9.8 |
CRITICAL
Network
|
apache
|
dolphinscheduler
|
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.
|
NVD-CWE-noinfo
|
CVE-2020-11974
|
2024-11-21 13:59 |
2020-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210553
|
6.5 |
MEDIUM
Adjacent
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system ser…
|
CWE-20
Improper Input Validation
|
CVE-2020-12521
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210554
|
9.8 |
CRITICAL
Network
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
|
CWE-269
Improper Privilege Management
|
CVE-2020-12519
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210555
|
5.5 |
MEDIUM
Local
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
|
CWE-200
Information Exposure
|
CVE-2020-12518
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210556
|
9.0 |
CRITICAL
Network
|
phoenixcontact
|
plcnext_firmware
|
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vu…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12517
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210557
|
9.1 |
CRITICAL
Network
|
phoenixcontact
|
tc_mguard_rs4000_4g_vzw_vpn_firmware tc_mguard_rs4000_4g_att_vpn_firmware fl_mguard_rs4004_tx\/dtx_firmware fl_mguard_rs4004_tx\/dtx_vpn_firmware tc_mguard_rs4000_3g_vpn_firmware tc_mg…
|
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the L…
|
CWE-909
Missing Initialization of Resource
|
CVE-2020-12523
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210558
|
9.8 |
CRITICAL
Network
|
wago
|
pfc_100_firmware pfc_200_firmware touch_panel_600_standard_firmware touch_panel_600_advanced_firmware touch_panel_600_marine_firmware
|
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/x…
|
CWE-78
OS Command
|
CVE-2020-12522
|
2024-11-21 13:59 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210559
|
6.8 |
MEDIUM
Network
|
arubanetworks
|
edgeconnect_enterprise
|
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, al…
|
CWE-78
OS Command
|
CVE-2020-12149
|
2024-11-21 13:59 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210560
|
6.8 |
MEDIUM
Network
|
arubanetworks
|
edgeconnect_enterprise
|
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web serv…
|
CWE-78
OS Command
|
CVE-2020-12148
|
2024-11-21 13:59 |
2020-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|