• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-10636
2022-03-07
N/A
7.5 HIGH
Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.
CVE-2020-10635
2022-03-04
N/A
4.3 MEDIUM
Simulation models for KUKA.Sim Pro version 3.1 are hosted by a server maintained by KUKA. When these devices request a model, the server transmits the model in plaintext.
CVE-2020-10634
Net-line Fw-50 Firmware, Sae-it
Net-line_fw-50_firmware, Net-line_fw-50
2020-05-12
N/A
9.1 CRITICAL
SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file structure of the affected device and access files that should be inaccessible.
CVE-2020-10633
Ewon Flexy Firmware, Hms-networks
Ewon_flexy_firmware, Ewon_flexy, Ewon_cosy_firmware, Ewon_cosy
2020-04-08
N/A
6.1 MEDIUM
A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful.
CVE-2020-10632
2022-03-07
N/A
5.3 MEDIUM
Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.
CVE-2020-10631
2020-04-10
N/A
9.8 CRITICAL
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
CVE-2020-10630
Net-line Fw-50 Firmware, Sae-it
Net-line_fw-50_firmware, Net-line_fw-50
2020-05-12
N/A
6.1 MEDIUM
SAE IT-systems FW-50 Remote Telemetry Unit (RTU). The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in the output used as a webpage that is served to other users.
CVE-2020-1063
2020-05-27
N/A
5.4 MEDIUM
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'.
CVE-2020-10629
2020-04-10
N/A
7.5 HIGH
WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.
CVE-2020-10628
Controledge Rtu Firmware, Honeywell
Hbd3pr2_firmware, Hbd3pr2, H4d3prv3_firmware, H4d3prv3, Hed3pr3_firmware, Hed3pr3, H4d3prv2_firmware, H4d3prv2, Hbd3pr1_firmware, Hbd3pr1
2020-07-07
N/A
7.5 HIGH
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
« Previous 1 … 4,892 4,893 4,894 4,895 4,896 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE