Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2020-7508
A CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which cou…
Easergy T300 Firmware
after 1.5.2
CRITICAL 9.8
CVE-2020-7512
A CWE-1103: Use of Platform-Dependent Third Party Components with vulnerabilities vulnerability exists in Easergy T300 (Firmware version 1.5.2 and ol…
Easergy T300 Firmware
after 1.5.2
HIGH 8.8
CVE-2020-7503
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…
Easergy T300 Firmware
after 1.5.2
HIGH 7.5
CVE-2020-7502
A CWE-787: Out-of-bounds Write vulnerability exists in Modicon M218 Logic Controller (Firmware version 4.3 and prior), which may cause a Denial of Se…
Modicon M218 Firmware
after 4.3
HIGH 7.5
CVE-2020-7506
A CWE-200: Information Exposure vulnerability exists in Easergy T300, Firmware V1.5.2 and prior, which could allow an attacker to pack or unpack the …
Easergy T300 Firmware
after 1.5.2
HIGH 7.5
CVE-2020-7507
A CWE-400: Uncontrolled Resource Consumption vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to…
Easergy T300 Firmware
after 1.5.2
HIGH 7.5
CVE-2020-7510
A CWE-200: Information Exposure vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow attacker to obtain private …
Easergy T300 Firmware
after 1.5.2
HIGH 7.5
CVE-2020-7511
A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow…
Easergy T300 Firmware
after 1.5.2
HIGH 7.5
CVE-2020-7513
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an at…
Easergy T300 Firmware
after 1.5.2
HIGH 7.2
CVE-2020-7505
A CWE-494 Download of Code Without Integrity Check vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attac…
Easergy T300 Firmware
after 1.5.2
HIGH 7.2
CVE-2020-7509
A CWE-269: Improper privilege management (write) vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacke…
Easergy T300 Firmware
after 1.5.2
MEDIUM 5.3
CVE-2020-7504
A CWE-20: Improper Input Validation vulnerability exists in Easergy T300 (Firmware version 1.5.2 and older) which could allow an attacker to disable …
Easergy T300 Firmware
after 1.5.2
CRITICAL 9.8
CVE-2020-7497
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert…
Ecostruxure Operator Terminal Expert
after 3.0
CRITICAL 9.8
CVE-2020-7498
A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader Software (all versions). The fixed credentials are us…
Os Loader
Mitigation only
CRITICAL 9.8
CVE-2020-7500
A CWE-89:Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in U.motion Servers and Touch Pane…
Mtn6501 0001 Firmware
1.4.2+
HIGH 8.8
CVE-2020-7501
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 16 and prior) and Vijeo Designer (V6.2 SP9 and pri…
Vijeo Designer
after 6.2
HIGH 7.8
CVE-2020-7493
A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal …
Ecostruxure Operator Terminal Expert
after 3.0
HIGH 7.8
CVE-2020-7494
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert…
Ecostruxure Operator Terminal Expert
after 3.0
MEDIUM 6.5
CVE-2020-7492
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when t…
Gp Pro Ex Firmware
after 4.09.120
MEDIUM 6.5
CVE-2020-7499
A CWE-863: Incorrect Authorization vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) …
Mtn6501 0001 Firmware
1.4.2+
MEDIUM 5.5
CVE-2020-7495
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxu…
Ecostruxure Operator Terminal Expert
after 3.0
CRITICAL 9.8
CVE-2020-7487
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modico…
Ecostruxure Machine Expert
Mitigation only
CRITICAL 9.8
CVE-2020-7489
A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Mach…
Ecostruxure Machine Expert
Patch available
HIGH 7.8
CVE-2020-7490
A CWE-426: Untrusted Search Path vulnerability exists in Vijeo Designer Basic (V1.1 HotFix 15 and prior) and Vijeo Designer (V6.9 SP9 and prior), whi…
Vijeo Designer
after 6.2
HIGH 7.5
CVE-2019-6859
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions of the following CPUs and Communication Module prod…
Bmx P34x Firmware
Mitigation only
HIGH 7.5
CVE-2020-7488
A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the softwa…
Ecostruxure Machine Expert
Mitigation only
CRITICAL 9.8
CVE-2020-7485
**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to…
Tristation 1131
after 4.9.0
HIGH 7.5
CVE-2020-7483
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled.…
Tristation 1131
after 4.12.0
HIGH 7.5
CVE-2020-7484
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability with the former 'password' feature could allow a denial of service attack if the user is not …
Tristation 1131
4.13.0+
HIGH 7.5
CVE-2020-7486
**VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause TCM modules to reset when under high network load in TCM v10.4.x and in system v1…
Tricon Tcm 4351 Firmware
Mitigation only