|
212521
|
8.8 |
HIGH
Adjacent
|
rockwellautomation
|
factorytalk_services_platform
|
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent a…
|
CWE-20
Improper Input Validation
|
CVE-2020-12033
|
2024-11-21 13:59 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212522
|
9.0 |
CRITICAL
Network
|
osisoft
|
pi_web_api
|
In OSIsoft PI Web API 2019 Patch 1 (1.12.0.6346) and all previous versions, the affected product is vulnerable to a cross-site scripting attack, which may allow an attacker to remotely execute arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-12021
|
2024-11-21 13:59 |
2020-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212523
|
9.8 |
CRITICAL
Network
|
unisys
|
stealth
|
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12053
|
2024-11-21 13:59 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212524
|
9.8 |
CRITICAL
Network
|
apache
|
shiro
|
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.
|
NVD-CWE-noinfo
|
CVE-2020-11989
|
2024-11-21 13:59 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212525
|
5.3 |
MEDIUM
Network
|
beckhoff
|
twincat_driver twincat
|
Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functional…
|
-
|
CVE-2020-12494
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212526
|
9.8 |
CRITICAL
Network
|
advantech
|
webaccess
|
WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-12019
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212527
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx rslinx_classic
|
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12005
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212528
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_linx rslinx_classic
|
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version …
|
CWE-22
Path Traversal
|
CVE-2020-12003
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212529
|
9.8 |
CRITICAL
Network
|
rockwellautomation
|
factorytalk_linx rslinx_classic
|
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version …
|
CWE-20
Improper Input Validation
|
CVE-2020-12001
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212530
|
9.8 |
CRITICAL
Network
|
apache
|
tomee
|
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication.…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11969
|
2024-11-21 13:59 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|