|
208591
|
8.4 |
HIGH
Local
|
solarwinds
|
n-central
|
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys …
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-25621
|
2024-11-21 14:18 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208592
|
7.8 |
HIGH
Local
|
solarwinds
|
n-central
|
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to t…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-25620
|
2024-11-21 14:18 |
2020-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208593
|
4.4 |
MEDIUM
Local
|
solarwinds
|
n-central
|
An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwardi…
|
NVD-CWE-Other
|
CVE-2020-25619
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208594
|
8.8 |
HIGH
Network
|
solarwinds
|
n-central
|
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as …
|
CWE-78
OS Command
|
CVE-2020-25618
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208595
|
8.8 |
HIGH
Network
|
solarwinds
|
n-central
|
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), le…
|
CWE-22
Path Traversal
|
CVE-2020-25617
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208596
|
8.8 |
HIGH
Network
|
dlink
|
dsr-150_firmware dsr-150n_firmware dsr-250_firmware dsr-250n_firmware dsr-500_firmware dsr-500n_firmware dsr-500ac_firmware dsr-1000_firmware dsr-1000n_firmware dsr-1000ac_…
|
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to …
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2020-25759
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208597
|
8.8 |
HIGH
Network
|
dlink
|
dsr-150_firmware dsr-150n_firmware dsr-250_firmware dsr-250n_firmware dsr-500_firmware dsr-500n_firmware dsr-500ac_firmware dsr-1000_firmware dsr-1000n_firmware dsr-1000ac_…
|
An issue was discovered on D-Link DSR-250 3.17 devices. Insufficient validation of configuration file checksums could allow a remote, authenticated attacker to inject arbitrary crontab entries into s…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-25758
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208598
|
8.8 |
HIGH
Adjacent
|
dlink
|
dsr-150_firmware dsr-150n_firmware dsr-250_firmware dsr-250n_firmware dsr-500_firmware dsr-500n_firmware dsr-500ac_firmware dsr-1000_firmware dsr-1000n_firmware dsr-1000ac_…
|
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with r…
|
CWE-20 CWE-78
Improper Input Validation OS Command
|
CVE-2020-25757
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208599
|
7.8 |
HIGH
Local
|
x.org redhat
|
x_server enterprise_linux
|
A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data …
|
-
|
CVE-2020-25712
|
2024-11-21 14:18 |
2020-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208600
|
6.5 |
MEDIUM
Network
|
microfocus
|
filr
|
Unauthorized disclosure of sensitive information vulnerability in Micro Focus Filr product. Affecting all 3.x and 4.x versions. The vulnerability could be exploited to disclose unauthorized sensitive…
|
NVD-CWE-noinfo
|
CVE-2020-25838
|
2024-11-21 14:18 |
2020-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|