Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2020-25842

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
Attacker Value
Unknown

CVE-2018-19944

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
A cleartext transmission of sensitive information vulnerability has been reported to affect certain QTS devices. If exploited, this vulnerability allows a remote attacker to gain access to sensitive information. QNAP have already fixed this vulnerability in the following versions: QTS 4.4.3.1354 build 20200702 (and later)
Attacker Value
Unknown

CVE-2020-35587

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative impact, or instead only facilitates an attack technique
Attacker Value
Unknown

CVE-2019-14480

Disclosure Date: December 16, 2020 (last updated February 22, 2025)
AdRem NetCrunch 10.6.0.4587 has an Improper Session Handling vulnerability in the NetCrunch web client, which can lead to an authentication bypass or escalation of privileges.
Attacker Value
Unknown

CVE-2020-27055

Disclosure Date: December 15, 2020 (last updated February 22, 2025)
In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there is a possible insecure WiFi configuration due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-161378819
Attacker Value
Unknown

CVE-2020-28216

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
Attacker Value
Unknown

CVE-2020-28217

Disclosure Date: December 11, 2020 (last updated February 22, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Easergy T300 (firmware 2.7 and older), that would allow an attacker to read network traffic over HTTP protocol.
Attacker Value
Unknown

CVE-2020-4126

Disclosure Date: December 01, 2020 (last updated February 22, 2025)
HCL iNotes is susceptible to a sensitive cookie exposure vulnerability. This can allow an unauthenticated remote attacker to capture the cookie by intercepting its transmission within an http session. Fixes are available in HCL Domino and iNotes versions 10.0.1 FP6 and 11.0.1 FP2 and later.
Attacker Value
Unknown

CVE-2020-7567

Disclosure Date: November 19, 2020 (last updated February 22, 2025)
A CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attacker to find the password hash when the attacker has captured the traffic between EcoStruxure Machine - Basic software and Modicon M221 controller and broke the encryption keys.
Attacker Value
Unknown

CVE-2020-8150

Disclosure Date: November 09, 2020 (last updated February 22, 2025)
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.