Show filters
194 Total Results
Displaying 61-70 of 194
Sort by:
Attacker Value
Unknown
CVE-2021-26938
Disclosure Date: February 10, 2021 (last updated February 22, 2025)
A stored XSS issue exists in henriquedornas 5.2.17 via online live chat. NOTE: Third parties report that no such product exists. That henriquedornas is the web design agency and 5.2.17 is simply the PHP version running on this hosts
0
Attacker Value
Unknown
CVE-2020-25704
Disclosure Date: December 02, 2020 (last updated February 22, 2025)
A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.
0
Attacker Value
Unknown
CVE-2020-27650
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.
0
Attacker Value
Unknown
CVE-2020-27652
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Algorithm downgrade vulnerability in QuickConnect in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-27648
Disclosure Date: October 29, 2020 (last updated February 22, 2025)
Improper certificate validation vulnerability in OpenVPN client in Synology DiskStation Manager (DSM) before 6.2.3-25426-2 allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2020-13364
Disclosure Date: August 06, 2020 (last updated November 28, 2024)
A backdoor in certain Zyxel products allows remote TELNET access via a CGI script. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.
0
Attacker Value
Unknown
CVE-2020-13365
Disclosure Date: August 06, 2020 (last updated February 21, 2025)
Certain Zyxel products have a locally accessible binary that allows a non-root user to generate a password for an undocumented user account that can be used for a TELNET session as root. This affects NAS520 V5.21(AASZ.4)C0, V5.21(AASZ.0)C0, V5.11(AASZ.3)C0, and V5.11(AASZ.0)C0; NAS542 V5.11(ABAG.0)C0, V5.20(ABAG.1)C0, and V5.21(ABAG.3)C0; NSA325 v2_V4.81(AALS.0)C0 and V4.81(AAAJ.1)C0; NSA310 4.22(AFK.0)C0 and 4.22(AFK.1)C0; NAS326 V5.21(AAZF.8)C0, V5.11(AAZF.4)C0, V5.11(AAZF.2)C0, and V5.11(AAZF.3)C0; NSA310S V4.75(AALH.2)C0; NSA320S V4.75(AANV.2)C0 and V4.75(AANV.1)C0; NSA221 V4.41(AFM.1)C0; and NAS540 V5.21(AATB.5)C0 and V5.21(AATB.3)C0.
0
Attacker Value
Unknown
CVE-2019-20807
Disclosure Date: May 28, 2020 (last updated February 21, 2025)
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
0
Attacker Value
Unknown
CVE-2017-18854
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
NETGEAR ReadyNAS 6.6.1 and earlier is affected by command injection.
Attacker Value
Unknown
CVE-2017-18856
Disclosure Date: April 29, 2020 (last updated February 21, 2025)
NETGEAR ReadyNAS devices before 6.6.1 are affected by command injection.
0