|
196101
|
6.4 |
MEDIUM
Network
|
phpoffice
|
phpspreadsheet
|
This affects the package phpoffice/phpspreadsheet from 0.0.0. The library is vulnerable to XSS when creating an html output from an excel file by adding a comment on any cell. The root cause of this …
|
CWE-79
Cross-site Scripting
|
CVE-2020-7776
|
2024-11-21 14:37 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196102
|
8.2 |
HIGH
Network
|
react-adal_project
|
react-adal
|
This affects all versions of package react-adal. It is possible for a specially crafted JWT token and request URL can cause the nonce, session and refresh values to be incorrectly validated, causing …
|
CWE-287
Improper Authentication
|
CVE-2020-7787
|
2024-11-21 14:37 |
2020-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196103
|
6.7 |
MEDIUM
Local
|
mcafee
|
virusscan_enterprise
|
Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through …
|
-
|
CVE-2020-7337
|
2024-11-21 14:37 |
2020-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196104
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
acti9_smartlink_si_d_firmware acti9_smartlink_si_b_firmware acti9_powertag_link_firmware acti9_powertag_link_hd_firmware acti9_smartlink_el_b_firmware wiser_link_firmware wiser_ener…
|
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorize…
|
-
|
CVE-2020-7548
|
2024-11-21 14:37 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196105
|
8.8 |
HIGH
Network
|
schneider-electric
|
ecostruxure_energy_expert ecostruxure_power_monitoring_expert power_manager powerscada_operation_with_advanced_reporting_and_dashboards powerscada_expert_with_advanced_reporting_and_dashb…
|
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a u…
|
NVD-CWE-Other
|
CVE-2020-7547
|
2024-11-21 14:37 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196106
|
5.4 |
MEDIUM
Network
|
schneider-electric
|
ecostruxure_energy_expert ecostruxure_power_monitoring_expert power_manager powerscada_operation_with_advanced_reporting_and_dashboards powerscada_expert_with_advanced_reporting_and_dashb…
|
A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for versio…
|
-
|
CVE-2020-7546
|
2024-11-21 14:37 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196107
|
7.2 |
HIGH
Network
|
schneider-electric
|
ecostruxure_energy_expert ecostruxure_power_monitoring_expert power_manager powerscada_operation_with_advanced_reporting_and_dashboards powerscada_expert_with_advanced_reporting_and_dashb…
|
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for …
|
NVD-CWE-Other
|
CVE-2020-7545
|
2024-11-21 14:37 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196108
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
modicon_m340_bmxp3420302_firmware modicon_m340_bmxp342000_firmware modicon_m340_bmxp341000_firmware modicon_m340_bmxp3420102_firmware bmxnoe0100_firmware bmxnoe0110_firmware bmxnoc0…
|
A CWE-255: Credentials Management vulnerability exists in Web Server on Modicon M340, Modicon Quantum and ModiconPremium Legacy offers and their Communication Modules (see security notification for v…
|
NVD-CWE-noinfo
|
CVE-2020-7533
|
2024-11-21 14:37 |
2020-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196109
|
7.8 |
HIGH
Local
|
mcafee
|
total_protection
|
Privilege Escalation vulnerability in Microsoft Windows client McAfee Total Protection (MTP) prior to 16.0.29 allows local users to gain elevated privileges via careful manipulation of a folder by cr…
|
-
|
CVE-2020-7335
|
2024-11-21 14:37 |
2020-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196110
|
8.8 |
HIGH
Network
|
softwaremill
|
akka-http-session
|
This affects the package com.softwaremill.akka-http-session:core_2.13 before 0.5.11; the package com.softwaremill.akka-http-session:core_2.12 before 0.5.11; the package com.softwaremill.akka-http-ses…
|
CWE-352
Origin Validation Error
|
CVE-2020-7780
|
2024-11-21 14:37 |
2020-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|