|
208261
|
5.4 |
MEDIUM
Network
|
tracefinanacial
|
crestbridge
|
Trace Financial CRESTBridge <6.3.0.02 contains a stored XSS vulnerability, which was fixed in 6.3.0.03.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24663
|
2024-11-21 14:15 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208262
|
5.4 |
MEDIUM
Network
|
smartstream
|
transaction_lifecycle_management_reconciliations-premium
|
SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM RP 3.1.0.
|
CWE-79
Cross-site Scripting
|
CVE-2020-24662
|
2024-11-21 14:15 |
2021-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208263
|
2.6 |
LOW
Adjacent
|
ieee linux debian arista cisco intel
|
ieee_802.11 mac80211 debian_linux c-100_firmware c-110_firmware c-120_firmware c-130_firmware c-200_firmware c-230_firmware c-235_firmware c-250_firmware c-260_firmwa…
|
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An a…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-24587
|
2024-11-21 14:15 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208264
|
3.5 |
LOW
Adjacent
|
ieee debian linux arista intel
|
ieee_802.11 debian_linux mac80211 c-250_firmware c-260_firmware c-230_firmware c-235_firmware c-200_firmware ax210_firmware ax201_firmware ax200_firmware ac_9560_firm…
|
The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting …
|
NVD-CWE-Other
|
CVE-2020-24586
|
2024-11-21 14:15 |
2021-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208265
|
9.8 |
CRITICAL
Network
|
arubanetworks siemens
|
instant scalance_w1750d_firmware
|
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.…
|
CWE-78
OS Command
|
CVE-2020-24636
|
2024-11-21 14:15 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208266
|
7.2 |
HIGH
Network
|
arubanetworks siemens
|
instant scalance_w1750d_firmware
|
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.…
|
CWE-78
OS Command
|
CVE-2020-24635
|
2024-11-21 14:15 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208267
|
7.5 |
HIGH
Network
|
abb
|
pm554_firmware pm556_firmware pm564_firmware pm566_firmware pm572_firmware pm573_firmware
|
The vulnerabilities can be exploited to cause the web visualization component of the PLC to stop and not respond, leading to genuine users losing remote visibility of the PLC state. If a user attempt…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-24686
|
2024-11-21 14:15 |
2021-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208268
|
8.8 |
HIGH
Network
|
mailtrain
|
mailtrain
|
Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.
|
CWE-89
SQL Injection
|
CVE-2020-24617
|
2024-11-21 14:15 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208269
|
8.6 |
HIGH
Network
|
abb
|
ac500_cpu_firmware
|
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-24685
|
2024-11-21 14:15 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208270
|
5.4 |
MEDIUM
Network
|
hitachi
|
vantara_pentaho
|
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24670
|
2024-11-21 14:15 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|