|
198421
|
7.5 |
HIGH
Network
|
schneider-electric
|
ecostruxure_control_expert
|
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC…
|
-
|
CVE-2020-7538
|
2024-11-21 14:37 |
2020-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198422
|
8.8 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their C…
|
-
|
CVE-2020-7564
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198423
|
8.8 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-787: Out-of-bounds Write vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details)…
|
-
|
CVE-2020-7563
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198424
|
8.1 |
HIGH
Network
|
schneider-electric
|
modicon_tsxety4103_firmware modicon_tsxety5103_firmware modicon_tsxp574634_firmware modicon_tsxp575634_firmware modicon_tsxp576634_firmware modicon_quantum_140noe77101_firmware modi…
|
A CWE-125: Out-of-Bounds Read vulnerability exists in the Web Server on Modicon M340, Modicon Quantum and Modicon Premium Legacy offers and their Communication Modules (see notification for details) …
|
-
|
CVE-2020-7562
|
2024-11-21 14:37 |
2020-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198425
|
8.8 |
HIGH
Network
|
tobesoft
|
xplatform
|
Improper input validation vulnerability exists in TOBESOFT XPLATFORM which could cause arbitrary .hta file execution when the command string is begun with http://, https://, mailto://
|
CWE-20
Improper Input Validation
|
CVE-2020-7841
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198426
|
9.8 |
CRITICAL
Network
|
y18n_project oracle siemens
|
y18n graalvm sinec_infrastructure_network_services
|
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-7774
|
2024-11-21 14:37 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198427
|
6.1 |
MEDIUM
Network
|
markdown-it-highlightjs_project
|
markdown-it-highlightjs
|
This affects the package markdown-it-highlightjs before 3.3.1. It is possible insert malicious JavaScript as a value of lang in the markdown-it-highlightjs Inline code highlighting feature. const mar…
|
CWE-79
Cross-site Scripting
|
CVE-2020-7773
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198428
|
5.3 |
MEDIUM
Network
|
google
|
firebase\/util
|
This affects the package @firebase/util before 0.3.4. This vulnerability relates to the deepExtend function within the DeepCopy.ts file. Depending on if user input is provided, an attacker can overwr…
|
NVD-CWE-noinfo
|
CVE-2020-7765
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198429
|
9.8 |
CRITICAL
Network
|
doc-path_project
|
doc-path
|
This affects the package doc-path before 2.1.2.
|
NVD-CWE-noinfo
|
CVE-2020-7772
|
2024-11-21 14:37 |
2020-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198430
|
9.8 |
CRITICAL
Network
|
sugarcrm
|
sugarcrm
|
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenti…
|
CWE-94 CWE-20
Code Injection Improper Input Validation
|
CVE-2020-7472
|
2024-11-21 14:37 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|