8.5

CVSS4.0

CVE-2020-36913 - All-Dynamics Software enlogic:show 2.0.2 Session Fixation Authentication Bypass

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentiallโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-36912 - Plexus anblick Digital Signage Management 3.1.13 Open Redirect via Pagina Parameter

Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validatioโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-36910 - Cayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP Parameter

Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2020-36909 - Secure Computing SnapGear Management Console SG560 3.1.5 Arbitrary File Read/Write

SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files โ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 6:59 p.m.

5.1

CVSS4.0

CVE-2020-36908 - Secure Computing SnapGear Management Console SG560 3.1.5 Cross-Site Request Forgery via Admin Users

SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full aโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: Feb. 23, 2026, 7 p.m.

8.7

CVSS4.0

CVE-2020-36907 - Extreme Networks Aerohive HiveOS <=11.x 11.x Unauthenticated Remote Denial of Service

Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2020-36906 - P5 FNIP-8x16A FNIP-4xSH 1.0.20 Cross-Site Request Forgery via User Management

P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticatโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-36905 - FIBARO System Home Center 5.021 Remote File Inclusion via Proxy API

FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulatโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.7

CVSS4.0

CVE-2026-0640 - Tenda AC23 PowerSaveSet sscanf buffer overflow

A weakness has been identified in Tenda AC23 16.03.07.52. This affects the function sscanf of the file /goform/PowerSaveSet. Executing a manipulation of the argument Time can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could beโ€ฆ

๐Ÿ“… Published: Jan. 6, 2026, 3:32 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 5 p.m.

8.5

CVSS4.0

CVE-2025-14979 - Eddie VPN 2.24.6 - Local Privilege Escalation

AirVPN Eddie on MacOS contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.This issue affects Eddie: 2.24.6.

๐Ÿ“… Published: Jan. 6, 2026, 3:15 p.m. ๐Ÿ”„ Last Modified: April 9, 2026, 9:17 p.m.
Total resulsts: 349182
Page 2272 of 34,919
ยซ previous page ยป next page
Filters