|
197131
|
3.7 |
LOW
Network
|
shipstation
|
shipstation
|
The ShipStation.com plugin 1.1 and earlier for CS-Cart allows remote attackers to insert arbitrary information into the database (via action=shipnotify) because access to this endpoint is completely …
|
CWE-862
Missing Authorization
|
CVE-2020-9009
|
2024-11-21 14:39 |
2023-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197132
|
7.5 |
HIGH
Network
|
shipstation
|
shipstation
|
The ShipStation.com plugin 1.0 for CS-Cart allows remote attackers to obtain sensitive information (via action=export) because a typo results in a successful comparison of a blank password and NULL.
|
NVD-CWE-noinfo
|
CVE-2020-8889
|
2024-11-21 14:39 |
2023-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197133
|
8.8 |
HIGH
Network
|
zigor
|
zgr_tps200_ng_firmware
|
The integrated server of the ZGR TPS200 NG on its 2.00 firmware version and 1.01 hardware version, allows a remote attacker to perform actions with the permissions of a victim user. For this to happe…
|
CWE-352
Origin Validation Error
|
CVE-2020-8976
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197134
|
7.5 |
HIGH
Network
|
zigor
|
zgr_tps200_ng_firmware
|
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, allows a remote attacker with access to the web application and knowledge of the routes (URIs) used by the application, to access…
|
CWE-200
Information Exposure
|
CVE-2020-8975
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197135
|
9.1 |
CRITICAL
Network
|
zigor
|
zgr_tps200_ng_firmware
|
In ZGR TPS200 NG 2.00 firmware version and 1.01 hardware version, the firmware upload process does not perform any type of restriction. This allows an attacker to modify it and re-upload it via web w…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8974
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197136
|
8.1 |
HIGH
Adjacent
|
zigor
|
zgr_tps200_ng_firmware
|
ZGR TPS200 NG in its 2.00 firmware version and 1.01 hardware version, does not properly accept specially constructed requests. This allows an attacker with access to the network where the affected as…
|
NVD-CWE-noinfo
|
CVE-2020-8973
|
2024-11-21 14:39 |
2022-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197137
|
3.1 |
LOW
Network
|
kubernetes
|
kubernetes
|
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Servi…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-8562
|
2024-11-21 14:39 |
2022-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197138
|
6.5 |
MEDIUM
Adjacent
|
aeotec samsung zooz silabs
|
zw090-a sth-eth-200 zst10 uzb-7 700_series_firmware 500_series_firmware
|
Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung …
|
NVD-CWE-noinfo
|
CVE-2020-9061
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197139
|
6.5 |
MEDIUM
Adjacent
|
silabs aeotec zooz fibaro
|
500_series_firmware zw090-a zst10 zen20 zen25 fgwpb-111
|
Z-Wave devices based on Silicon Labs 500 series chipsets using S2, including but likely not limited to the ZooZ ZST10 version 6.04, ZooZ ZEN20 version 5.03, ZooZ ZEN25 version 5.03, Aeon Labs ZW090-A…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-9060
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197140
|
6.5 |
MEDIUM
Adjacent
|
silabs schlage
|
500_series_firmware be468
|
Z-Wave devices based on Silicon Labs 500 series chipsets using S0 authentication are susceptible to uncontrolled resource consumption leading to battery exhaustion. As an example, the Schlage BE468 v…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-9059
|
2024-11-21 14:39 |
2022-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|