|
210781
|
5.5 |
MEDIUM
Local
|
siemens
|
simatic_pcs_7 simatic_wincc
|
A vulnerability has been identified in SIMATIC PCS 7 (All versions), SIMATIC WinCC (All versions < V7.5 SP2). Due to an insecure password verification process, an attacker could bypass the password p…
|
CWE-287
Improper Authentication
|
CVE-2020-10048
|
2024-11-21 13:54 |
2021-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210782
|
8.1 |
HIGH
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows man-in-…
|
CWE-78
OS Command
|
CVE-2020-10209
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210783
|
9.9 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows authenticated remote attackers to execute a…
|
CWE-78 CWE-74
OS Command Injection
|
CVE-2020-10208
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210784
|
4.4 |
MEDIUM
Local
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows local attackers to view and interact w…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10206
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210785
|
9.8 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Because of hard-coded SSH keys for the root user in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series, Kami7B, an attacker may remotely log in through …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10210
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210786
|
9.8 |
CRITICAL
Network
|
amino
|
ak45x_firmware ak5xx_firmware ak65x_firmware aria6xx_firmware aria7xx_firmware kami7b_firmware
|
Use of Hard-coded Credentials in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, Aria7/AK7Xx series and Kami7B allows remote attackers to retrieve an…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-10207
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210787
|
9.8 |
CRITICAL
Network
|
solarwinds
|
orion_platform
|
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authenticatio…
|
CWE-287
Improper Authentication
|
CVE-2020-10148
|
2024-11-21 13:54 |
2020-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210788
|
7.8 |
HIGH
Local
|
macrium
|
reflect
|
Macrium Reflect includes an OpenSSL component that specifies an OPENSSLDIR variable as C:\openssl\. Macrium Reflect contains a privileged service that uses this OpenSSL component. Because unprivilege…
|
CWE-665
Improper Initialization
|
CVE-2020-10143
|
2024-11-21 13:54 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210789
|
5.4 |
MEDIUM
Network
|
microsoft
|
teams
|
The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as aut…
|
CWE-79
Cross-site Scripting
|
CVE-2020-10146
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210790
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x tvos iphone_os watchos ipados
|
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted au…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-10017
|
2024-11-21 13:54 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|