|
209621
|
7.5 |
HIGH
Network
|
reolink
|
rln8-410_firmware rlc-422_firmware rlc-510a_firmware rlc-410_firmware rlc-423s_firmware rlc-423_firmware rlc-520a_firmware
|
The affected Reolink P2P products do not sufficiently protect data transferred between the local device and Reolink servers. This can allow an attacker to access sensitive information, such as camera…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-25169
|
2024-11-21 14:17 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209622
|
6.1 |
MEDIUM
Network
|
nagios
|
log_server
|
Nagios Log Server 2.1.7 contains a cross-site scripting (XSS) vulnerability in /nagioslogserver/configure/create_snapshot through the snapshot_name parameter, which may impact users who open a malici…
|
CWE-79
Cross-site Scripting
|
CVE-2020-25385
|
2024-11-21 14:17 |
2021-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209623
|
9.8 |
CRITICAL
Network
|
siemens
|
scalance_x200-4pirt_firmware scalance_x201-3pirt_firmware scalance_x202-2irt_firmware scalance_x202-2pirt_firmware scalance_x202-2pirt_siplus_net_firmware scalance_x204irt_firmware …
|
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (All versions < V5.2.5), SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5…
|
-
|
CVE-2020-25226
|
2024-11-21 14:17 |
2021-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209624
|
7.5 |
HIGH
Network
|
dovecot debian fedoraproject
|
dovecot debian_linux fedora
|
Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
|
CWE-20
Improper Input Validation
|
CVE-2020-25275
|
2024-11-21 14:17 |
2021-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209625
|
8.8 |
HIGH
Network
|
moxa
|
nport_iaw5000a-i\/o_firmware
|
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has incorrectly implemented protections from session fixation, which may allow an attacker to gain access to a sessio…
|
CWE-384
Session Fixation
|
CVE-2020-25198
|
2024-11-21 14:17 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209626
|
9.8 |
CRITICAL
Network
|
moxa
|
nport_iaw5000a-i\/o_firmware
|
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows SSH/Telnet sessions, which may be vulnerable to brute force attacks to bypass authentication.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-25196
|
2024-11-21 14:17 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209627
|
8.8 |
HIGH
Network
|
moxa
|
nport_iaw5000a-i\/o_firmware
|
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower has improper privilege management, which may allow an attacker with user privileges to perform requests with administ…
|
CWE-269
Improper Privilege Management
|
CVE-2020-25194
|
2024-11-21 14:17 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209628
|
5.3 |
MEDIUM
Network
|
moxa
|
nport_iaw5000a-i\/o_firmware
|
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower allows sensitive information to be displayed without proper authorization.
|
CWE-200
Information Exposure
|
CVE-2020-25192
|
2024-11-21 14:17 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209629
|
9.8 |
CRITICAL
Network
|
moxa
|
nport_iaw5000a-i\/o_firmware
|
The built-in WEB server for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower stores and transmits the credentials of third-party services in cleartext.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-25190
|
2024-11-21 14:17 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209630
|
7.5 |
HIGH
Network
|
moxa
|
nport_iaw5000a-i\/o_firmware
|
The built-in web service for MOXA NPort IAW5000A-I/O firmware version 2.1 or lower does not require users to have strong passwords.
|
CWE-521
Weak Password Requirements
|
CVE-2020-25153
|
2024-11-21 14:17 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|