|
198471
|
7.5 |
HIGH
Network
|
hcc-embedded siemens
|
nichestack 7km9300-0ae02-0aa0_firmware
|
An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the ICMP checksum. When …
|
CWE-125
Out-of-bounds Read
|
CVE-2020-35683
|
2024-11-21 14:27 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198472
|
9.1 |
CRITICAL
Network
|
hcc-embedded siemens
|
nichestack sentron_3wa_com190_firmware sentron_3wl_com35_firmware
|
An issue was discovered in HCC Nichestack 3.0. The code that generates Initial Sequence Numbers (ISNs) for TCP connections derives the ISN from an insufficiently random source. As a result, an attack…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-35685
|
2024-11-21 14:27 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198473
|
7.5 |
HIGH
Network
|
hcc-embedded siemens
|
nichestack sentron_3wl_com35_firmware sentron_3wa_com190_firmware
|
An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the length of the TCP pay…
|
CWE-20
Improper Input Validation
|
CVE-2020-35684
|
2024-11-21 14:27 |
2021-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198474
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
employee_record_management_system
|
SQL injection vulnerability in PHPGurukul Employee Record Management System 1.1 allows remote attackers to execute arbitrary SQL commands and bypass authentication.
|
CWE-89
SQL Injection
|
CVE-2020-35427
|
2024-11-21 14:27 |
2021-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198475
|
6.1 |
MEDIUM
Network
|
fiyo
|
fiyo_cms
|
In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-35373
|
2024-11-21 14:27 |
2021-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198476
|
7.3 |
HIGH
Network
|
apache debian fedoraproject oracle
|
http_server debian_linux fedora instantis_enterprisetrack enterprise_manager_ops_center zfs_storage_appliance_kit
|
Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP …
|
CWE-787
Out-of-bounds Write
|
CVE-2020-35452
|
2024-11-21 14:27 |
2021-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198477
|
9.8 |
CRITICAL
Network
|
fangfa
|
fdcms
|
FDCMS (also known as Fangfa Content Management System) 4.0 allows remote attackers to get a webshell in the background via Front/lib/Action/FindexAction.class.php.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-35442
|
2024-11-21 14:27 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198478
|
9.8 |
CRITICAL
Network
|
fangfa
|
fdcms
|
FDCMS (aka Fangfa Content Management System) 4.0 contains a front-end SQL injection via Admin/Lib/Action/FloginAction.class.php.
|
CWE-89
SQL Injection
|
CVE-2020-35441
|
2024-11-21 14:27 |
2021-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198479
|
7.0 |
HIGH
Local
|
redhat
|
openshift
|
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local …
|
-
|
CVE-2020-35514
|
2024-11-21 14:27 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198480
|
5.9 |
MEDIUM
Network
|
redhat
|
jboss-remoting
|
A flaw was found in jboss-remoting in versions before 5.0.20.SP1-redhat-00001. A malicious attacker could cause threads to hold up forever in the EJB server by writing a sequence of bytes correspondi…
|
-
|
CVE-2020-35510
|
2024-11-21 14:27 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|