Show filters
55 Total Results
Displaying 21-30 of 55
Sort by:
Attacker Value
Unknown

CVE-2020-12514

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd
Attacker Value
Unknown

CVE-2020-12511

Disclosure Date: January 04, 2021 (last updated February 22, 2025)
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a Cross-Site Request Forgery (CSRF) in the web interface.
Attacker Value
Unknown

CVE-2020-7201

Disclosure Date: December 18, 2020 (last updated February 22, 2025)
A potential security vulnerability has been identified in the HPE StoreEver MSL2024 Tape Library and HPE StoreEver 1/8 G2 Tape Autoloaders. The vulnerability could be remotely exploited to allow Cross-site Request Forgery (CSRF).
Attacker Value
Unknown

CVE-2020-28930

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.
Attacker Value
Unknown

CVE-2020-28931

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.
Attacker Value
Unknown

CVE-2020-28929

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.
Attacker Value
Unknown

CVE-2020-12330

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2020-10136 — IP-in-IP protocol routes arbitrary traffic by default

Disclosure Date: June 01, 2020 (last updated February 21, 2025)
IP-in-IP protocol specifies IP Encapsulation within IP standard (RFC 2003, STD 1) that decapsulate and route IP-in-IP traffic is vulnerable to spoofing, access-control bypass and other unexpected behavior due to the lack of validation to verify network packets before decapsulation and routing.
Attacker Value
Unknown

CVE-2019-14609

Disclosure Date: December 16, 2019 (last updated November 27, 2024)
Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2019-14611

Disclosure Date: December 16, 2019 (last updated November 27, 2024)
Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.