|
209471
|
6.8 |
MEDIUM
Physics
|
solokeys nitrokey
|
solo_firmware somu_firmware fido2_firmware
|
The flash read-out protection (RDP) level is not enforced during the device initialization phase of the SoloKeys Solo 4.0.0 & Somu and the Nitrokey FIDO2 token. This allows an adversary to downgrade …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-27208
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209472
|
7.5 |
HIGH
Network
|
micro-ecc_project
|
micro-ecc
|
The ECDSA operation of the micro-ecc library 1.0 is vulnerable to simple power analysis attacks which allows an adversary to extract the private ECC key.
|
NVD-CWE-noinfo
|
CVE-2020-27209
|
2024-11-21 14:20 |
2021-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209473
|
7.5 |
HIGH
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
Cleartext transmission of sensitive information via Moxa Service in NPort IA5000A series serial devices. Successfully exploiting the vulnerability could enable attackers to read authentication data, …
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-27185
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209474
|
5.9 |
MEDIUM
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
The NPort IA5000A Series devices use Telnet as one of the network device management services. Telnet does not support the encryption of client-server communications, making it vulnerable to Man-in-th…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-27184
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209475
|
7.5 |
HIGH
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
In multiple versions of NPort IA5000A Series, the result of exporting a device’s configuration contains the passwords of all users on the system and other sensitive data in the original form if “Pre-…
|
NVD-CWE-noinfo
|
CVE-2020-27150
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209476
|
6.5 |
MEDIUM
Network
|
moxa
|
nport_ia5150a_firmware nport_ia5250a_firmware nport_ia5450a_firmware
|
By exploiting a vulnerability in NPort IA5150A/IA5250A Series before version 1.5, a user with “Read Only” privilege level can send requests via the web console to have the device’s configuration chan…
|
NVD-CWE-noinfo
|
CVE-2020-27149
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209477
|
7.5 |
HIGH
Network
|
kaspersky
|
password_manager
|
Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker woul…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-27020
|
2024-11-21 14:20 |
2021-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209478
|
8.8 |
HIGH
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authen…
|
CWE-89
SQL Injection
|
CVE-2020-27246
|
2024-11-21 14:20 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209479
|
8.8 |
HIGH
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenti…
|
CWE-89
SQL Injection
|
CVE-2020-27245
|
2024-11-21 14:20 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209480
|
8.8 |
HIGH
Network
|
openclinic_ga_project
|
openclinic_ga
|
An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authentic…
|
CWE-89
SQL Injection
|
CVE-2020-27244
|
2024-11-21 14:20 |
2021-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|