|
197021
|
7.8 |
HIGH
Local
|
schneider-electric
|
operator_terminal_expert_runtime
|
A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting dire…
|
-
|
CVE-2020-7544
|
2024-11-21 14:37 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197022
|
7.5 |
HIGH
Network
|
schneider-electric
|
ecostruxure_control_expert
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC…
|
-
|
CVE-2020-7538
|
2024-11-21 14:37 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197023
|
8.8 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their C…
|
-
|
CVE-2020-7564
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197024
|
8.8 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details)…
|
-
|
CVE-2020-7563
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197025
|
8.1 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) …
|
-
|
CVE-2020-7562
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197026
|
8.8 |
HIGH
Network
|
tobesoft
|
xplatform
|
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://
|
CWE-20
Improper Input Validation
|
CVE-2020-7841
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197027
|
9.8 |
CRITICAL
Network
|
y18n_project oracle siemens
|
y18n graalvm sinec_infrastructure_network_services
|
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7774
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197028
|
6.1 |
MEDIUM
Network
|
markdown-it-highlightjs_project
|
markdown-it-highlightjs
|
This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const mar…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7773
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197029
|
5.3 |
MEDIUM
Network
|
google
|
firebase\/util
|
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwr…
|
NVD-CWE-noinfo
|
CVE-2020-7765
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197030
|
9.8 |
CRITICAL
Network
|
doc-path_project
|
doc-path
|
This affects the package doc-path before 2.1.2.
|
NVD-CWE-noinfo
|
CVE-2020-7772
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|