|
208801
|
8.8 |
HIGH
Network
|
schneider-electric rockwellautomation xylem
|
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<…
|
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploadin…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-25178
|
2024-11-21 14:17 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208802
|
9.8 |
CRITICAL
Network
|
schneider-electric rockwellautomation xylem
|
easergy_t300_firmware easergy_c5_firmware micom_c264_firmware pacis_gtw_firmware saitel_dp_firmware epas_gtw_firmware saitel_dr_firmware scd2200_firmware isagraf_free_runtime<…
|
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to th…
|
CWE-22
Path Traversal
|
CVE-2020-25176
|
2024-11-21 14:17 |
2022-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208803
|
5.5 |
MEDIUM
Local
|
gpac
|
gpac
|
A Null pointer dereference vulnerability exits in MP4Box - GPAC version 0.8.0-rev177-g51a8ef874-master via the gf_isom_get_track_id function, which causes a denial of service.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-25427
|
2024-11-21 14:17 |
2022-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208804
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-823g_firmware
|
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacter…
|
CWE-78
OS Command
|
CVE-2020-25368
|
2024-11-21 14:17 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208805
|
9.1 |
CRITICAL
Network
|
dlink
|
dir-823g_firmware
|
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows attackers to cause a denial of service (DoS) via unspecified vectors.
|
CWE-862
Missing Authorization
|
CVE-2020-25366
|
2024-11-21 14:17 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208806
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-823g_firmware
|
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacter…
|
CWE-78
OS Command
|
CVE-2020-25367
|
2024-11-21 14:17 |
2021-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208807
|
5.4 |
MEDIUM
Network
|
mara_cms_project
|
mara_cms
|
A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-25422
|
2024-11-21 14:17 |
2021-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208808
|
9.1 |
CRITICAL
Network
|
rconfig
|
rconfig
|
An arbitrary file deletion vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability gave attackers the ability to send a crafted request to /lib/ajaxHandlers/ajaxDeleteAllLoggingFi…
|
CWE-862
Missing Authorization
|
CVE-2020-25359
|
2024-11-21 14:17 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208809
|
6.5 |
MEDIUM
Network
|
rconfig
|
rconfig
|
A server-side request forgery (SSRF) vulnerability in rConfig 3.9.5 has been fixed for 3.9.6. This vulnerability allowed remote authenticated attackers to open a connection to the machine via the dev…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-25353
|
2024-11-21 14:17 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208810
|
5.4 |
MEDIUM
Network
|
rconfig
|
rconfig
|
A stored cross-site scripting (XSS) vulnerability in the /devices.php function inrConfig 3.9.5 has been fixed for version 3.9.6. This vulnerability allowed remote attackers to perform arbitrary Javas…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25352
|
2024-11-21 14:17 |
2021-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|