|
208121
|
6.1 |
MEDIUM
Network
|
eclipse
|
hawkbit
|
In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe characters within the path attribute. Sending a POST reques…
|
CWE-79
Cross-site Scripting
|
CVE-2020-27219
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208122
|
5.4 |
MEDIUM
Network
|
skyworth
|
gn542vf_firmware
|
Cross Site Scripting (XSS) in Configuration page in SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 allows authenticated attacker to inject their own script into the page via DDNS…
|
CWE-79
Cross-site Scripting
|
CVE-2020-26733
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208123
|
7.5 |
HIGH
Network
|
skyworth
|
gn542vf_boa_firmware
|
SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-26732
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208124
|
8.8 |
HIGH
Network
|
eclipse
|
hono
|
The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a…
|
CWE-862
Missing Authorization
|
CVE-2020-27220
|
2024-11-21 14:20 |
2021-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208125
|
9.1 |
CRITICAL
Network
|
ptc ge rockwellautomation softwaretoolbox
|
opc-aggregator thingworx_industrial_connectivity thingworx_kepware_server kepware_kepserverex industrial_gateway_server kepserver_enterprise top_server
|
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27267
|
2024-11-21 14:20 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208126
|
9.8 |
CRITICAL
Network
|
ptc ge rockwellautomation softwaretoolbox
|
opc-aggregator thingworx_industrial_connectivity thingworx_kepware_server kepware_kepserverex industrial_gateway_server kepserver_enterprise top_server
|
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27265
|
2024-11-21 14:20 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208127
|
9.1 |
CRITICAL
Network
|
ptc ge rockwellautomation softwaretoolbox
|
opc-aggregator thingworx_industrial_connectivity thingworx_kepware_server kepware_kepserverex industrial_gateway_server kepserver_enterprise top_server
|
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-27263
|
2024-11-21 14:20 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208128
|
8.8 |
HIGH
Network
|
siemens
|
teamcenter_visualization jt2go
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsi…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-26996
|
2024-11-21 14:20 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208129
|
8.8 |
HIGH
Network
|
siemens
|
teamcenter_visualization jt2go
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsi…
|
-
|
CVE-2020-26995
|
2024-11-21 14:20 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208130
|
8.8 |
HIGH
Network
|
siemens
|
teamcenter_visualization jt2go
|
A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsi…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26994
|
2024-11-21 14:20 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|