|
209061
|
8.6 |
HIGH
Network
|
abb
|
ac500_cpu_firmware
|
An unauthenticated specially crafted packet sent by an attacker over the network will cause a denial-of-service (DoS) vulnerability. Vulnerability allows attacker to stop the PLC. After stopping (ERR…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-24685
|
2024-11-21 14:15 |
2021-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209062
|
5.4 |
MEDIUM
Network
|
hitachi
|
vantara_pentaho
|
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24670
|
2024-11-21 14:15 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209063
|
5.4 |
MEDIUM
Network
|
hitachi
|
vantara_pentaho
|
The New Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a DOM-based Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScrip…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24669
|
2024-11-21 14:15 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209064
|
5.4 |
MEDIUM
Network
|
hitachi
|
vantara_pentaho
|
The Analysis Report in Hitachi Vantara Pentaho through 7.x - 8.x contains a stored Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript code.…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24666
|
2024-11-21 14:15 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209065
|
6.5 |
MEDIUM
Network
|
hitachi
|
vantara_pentaho
|
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity Expansion injection vulnerability, which allows an authenticated remote users to trigger a denial of service (…
|
CWE-776
XML Entity Expansion
|
CVE-2020-24665
|
2024-11-21 14:15 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209066
|
5.4 |
MEDIUM
Network
|
hitachi
|
vantara_pentaho
|
The dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains a reflected Cross-site scripting vulnerability, which allows an authenticated remote users to execute arbitrary JavaScript c…
|
CWE-79
Cross-site Scripting
|
CVE-2020-24664
|
2024-11-21 14:15 |
2021-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209067
|
7.5 |
HIGH
Network
|
arubanetworks
|
airwave_glass
|
In Aruba AirWave Glass before 1.3.3, there is a Server-Side Request Forgery vulnerability through an unauthenticated endpoint that if successfully exploited can result in disclosure of sensitive info…
|
CWE-287 CWE-918
Improper Authentication Server-Side Request Forgery (SSRF)
|
CVE-2020-24641
|
2024-11-21 14:15 |
2021-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209068
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
airwave_glass
|
There is a vulnerability caused by insufficient input validation that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation …
|
NVD-CWE-noinfo
|
CVE-2020-24640
|
2024-11-21 14:15 |
2021-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209069
|
9.8 |
CRITICAL
Network
|
arubanetworks
|
airwave_glass
|
There is a vulnerability caused by unsafe Java deserialization that allows for arbitrary command execution in a containerized environment within Airwave Glass before 1.3.3. Successful exploitation ca…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-24639
|
2024-11-21 14:15 |
2021-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209070
|
7.2 |
HIGH
Network
|
arubanetworks
|
airwave_glass
|
Multiple authenticated remote command executions are possible in Airwave Glass before 1.3.3 via the glassadmin cli. These allow for a user with glassadmin privileges to execute arbitrary code as root…
|
NVD-CWE-noinfo
|
CVE-2020-24638
|
2024-11-21 14:15 |
2021-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|