Latest CVE Feed
-
9.8
CRITICALCVE-2020-12106
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows unauthenticated users to send HTTP POST request to several critical Administrative functions such as, changing credentials of the Administrator account or connect the product to a rogue access... Read more
- Published: Aug. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12126
Multiple authentication bypass vulnerabilities in the /cgi-bin/ endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allow an attacker to leak router settings, change configuration variables, and cause denial of service via an unauthenticated endpoint.... Read more
- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12053
In Unisys Stealth 3.4.x, 4.x and 5.x before 5.0.026, if certificate-based authorization is used without HTTPS, an endpoint could be authorized without a private key.... Read more
Affected Products : stealth- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12022
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. An improper validation vulnerability exists that could allow an attacker to inject specially crafted input into memory where it can be executed.... Read more
Affected Products : webaccess- Published: May. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12043
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.... Read more
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12017
GE Grid Solutions Reason RT Clocks, RT430, RT431, and RT434, all firmware versions prior to 08A05. The device’s vulnerability in the web application could allow multiple unauthenticated attacks that could cause serious impact. The vulnerability may allow ... Read more
- Published: Jun. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12007
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.3... Read more
Affected Products : genesis32 genesis64 mc_works64 bizviz mc_works mc_works32 energy_analytix facility_analytix hyper_historian mobilehmi +2 more products- Published: Jul. 16, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11989
Apache Shiro before 1.5.3, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.... Read more
Affected Products : shiro- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12019
WebAccess Node Version 8.4.4 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code.... Read more
Affected Products : webaccess- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12040
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational... Read more
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11981
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbitrary commands.... Read more
Affected Products : airflow- Published: Jul. 17, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12045
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials.... Read more
- Published: Jun. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11973
Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0.... Read more
- Published: May. 14, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11986
To be able to analyze gradle projects, the build scripts need to be executed. Apache NetBeans follows this pattern. This causes the code of the build script to be invoked at load time of the project. Apache NetBeans up to and including 12.0 did not reques... Read more
Affected Products : netbeans- Published: Sep. 09, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11966
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the f... Read more
- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11967
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating ... Read more
- Published: Apr. 21, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11969
If Apache TomEE is configured to use the embedded ActiveMQ broker, and the broker URI includes the useJMX=true parameter, a JMX port is opened on TCP port 1099, which does not include authentication. This affects Apache TomEE 8.0.0-M1 - 8.0.1, Apache TomE... Read more
Affected Products : tomee- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11942
An issue was discovered in Open-AudIT 3.2.2. There are Multiple SQL Injections.... Read more
Affected Products : open-audit- Published: Apr. 29, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-12001
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and lat... Read more
- Published: Jun. 15, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2020-11974
In DolphinScheduler 1.2.0 and 1.2.1, with mysql connectorj a remote code execution vulnerability exists when choosing mysql as database.... Read more
Affected Products : dolphinscheduler- Published: Dec. 18, 2020
- Modified: Nov. 21, 2024