
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-2501 | Published 2021-02-17 | CVSS: 9.8 | ShadowTrackr CVSS: 8.2 | Summary: A stack-based buffer overflow vulnerability has been reported to affect QNAP NAS devices running Surveillance Station. If exploited, this vulnerability allows attackers to execute arbitrary code. QNAP have already fixed this vulnerability in the following versions: Surveillance Station 5.1.5.4.3 (and later) for ARM CPU NAS (64bit OS) and x86 CPU NAS (64bit OS) Surveillance Station 5.1.5.3.3 (and later) for ARM CPU NAS (32bit OS) and x86 CPU NAS (32bit OS) |
CVE: CVE-2020-25011 | Published 2020-12-17 | CVSS: 9.8 | ShadowTrackr CVSS: 7.2 | Summary: A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and password by request /cgi-bin/webadminget.cgi script via the browser. |
CVE: CVE-2020-25010 | Published 2020-12-17 | CVSS: 9.8 | ShadowTrackr CVSS: 7.2 | Summary: An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a file. |
CVE: CVE-2020-25014 | Published 2020-11-27 | CVSS: 9.8 | ShadowTrackr CVSS: 7.2 | Summary: A stack-based buffer overflow in fbwifi_continue.cgi on Zyxel UTM and VPN series of gateways running firmware version V4.30 through to V4.55 allows remote unauthenticated attackers to execute arbitrary code via a crafted http packet. |
CVE: CVE-2020-25013 | Published 2020-11-16 | CVSS: 7.5 | ShadowTrackr CVSS: 4.6 | Summary: JetBrains ToolBox before version 1.18 is vulnerable to a Denial of Service attack via a browser protocol handler. |
CVE: CVE-2020-25018 | Published 2020-10-01 | CVSS: 7.5 | ShadowTrackr CVSS: 4.6 | Summary: Envoy master between 2d69e30 and 3b5acb2 may fail to parse request URL that requires host canonicalization. |
CVE: CVE-2020-25017 | Published 2020-10-01 | CVSS: 8.3 | ShadowTrackr CVSS: 1.7 | Summary: Envoy through 1.15.0 only considers the first value when multiple header values are present for some HTTP headers. Envoy’s setCopy() header map API does not replace all existing occurences of a non-inline header. |
CVE: CVE-2020-25015 | Published 2020-09-16 | CVSS: 6.5 | ShadowTrackr CVSS: 5.0 | Summary: A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password. |
CVE: CVE-2020-25019 | Published 2020-08-29 | CVSS: 7.5 | ShadowTrackr CVSS: 6.9 | Summary: jitsi-meet-electron (aka Jitsi Meet Electron) before 2.3.0 calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances. |
CVE: CVE-2020-25016 | Published 2020-08-29 | CVSS: 9.1 | ShadowTrackr CVSS: 8.1 | Summary: A safety violation was discovered in the rgb crate before 0.8.20 for Rust, leading to (for example) dereferencing of arbitrary pointers or disclosure of uninitialized memory. This occurs because structs can be treated as bytes for read and write operations. |