|
208271
|
9.8 |
CRITICAL
Network
|
grandstream
|
grp2612_firmware grp2612p_firmware grp2612w_firmware grp2613_firmware grp2614_firmware grp2615_firmware grp2616_firmware
|
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication Bypass in its administrative web interface.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-25218
|
2024-11-21 14:17 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208272
|
7.2 |
HIGH
Network
|
grandstream
|
grp2612_firmware grp2612p_firmware grp2612w_firmware grp2613_firmware grp2614_firmware grp2615_firmware grp2616_firmware
|
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
|
CWE-77
Command Injection
|
CVE-2020-25217
|
2024-11-21 14:17 |
2021-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208273
|
8.6 |
HIGH
Network
|
squid-cache debian fedoraproject netapp
|
squid debian_linux fedora cloud_manager
|
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbi…
|
CWE-20 CWE-444
Improper Input Validation HTTP Request Smuggling
|
CVE-2020-25097
|
2024-11-21 14:17 |
2021-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208274
|
7.5 |
HIGH
Network
|
siemens
|
simatic_mv440_sr_firmware simatic_mv440_hr_firmware simatic_mv440_ur_firmware simatic_mv420_sr-b_firmware simatic_mv420_sr-p_firmware simatic_mv420_sr-b_body_firmware simatic_mv420_…
|
A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). The underlying TCP stack of the affected products does not correctly validate the sequence number for incoming TCP…
|
CWE-129
Improper Validation of Array Index
|
CVE-2020-25241
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208275
|
8.8 |
HIGH
Network
|
siemens
|
sinema_remote_connect_server
|
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). Unpriviledged users can access services when guessing the url. An attacker could impact availability, integr…
|
-
|
CVE-2020-25240
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208276
|
8.8 |
HIGH
Network
|
siemens
|
sinema_remote_connect_server
|
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0). The webserver could allow unauthorized actions via special urls for unpriviledged users. The settings of the…
|
-
|
CVE-2020-25239
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208277
|
5.5 |
MEDIUM
Local
|
siemens
|
logo\!_8_bm_firmware
|
A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA1) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA1) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA1) (All versions), LOGO!…
|
-
|
CVE-2020-25236
|
2024-11-21 14:17 |
2021-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208278
|
8.8 |
HIGH
Network
|
advantech
|
webaccess\/scada
|
The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an adminis…
|
CWE-610
Externally Controlled Reference to a Resource in Another Sphere
|
CVE-2020-25161
|
2024-11-21 14:17 |
2021-02-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208279
|
7.8 |
HIGH
Local
|
fujielectric
|
v-server
|
The affected Fuji Electric V-Server Lite versions prior to 3.3.24.0 are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-25171
|
2024-11-21 14:17 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208280
|
5.5 |
MEDIUM
Local
|
nfstream
|
nfstream
|
An issue was discovered in NFStream 5.2.0. Because some allocated modules are not correctly freed, if the nfstream object is directly destroyed without being used after it is created, it will cause a…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-25340
|
2024-11-21 14:17 |
2021-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|