7

CVSS4.0

CVE-2026-0715 - Bootloader Password Disclosure Allows Physical Device Denial-of-Service

Moxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An attacker with physical access to the device could use this information to access the bootloader menu via a serial interface.  Access to the bootloader menu doe…

📅 Published: Feb. 5, 2026, 5:01 p.m. 🔄 Last Modified: April 18, 2026, 1:45 p.m.

7

CVSS4.0

CVE-2026-0714 -

A physical attack vulnerability exists in certain Moxa industrial computers using TPM-backed LUKS full-disk encryption on Moxa Industrial Linux 3, where the discrete TPM is connected to the CPU via an SPI bus. Exploitation requires invasive physical access, including opening the device and attachin…

📅 Published: Feb. 5, 2026, 4:58 p.m. 🔄 Last Modified: April 17, 2026, 11:15 p.m.

5.1

CVSS4.0

CVE-2020-37148 - P5 FNIP-8x16A/FNIP-4xSH 1.0.20, 1.0.11 - Stored Cross-Site Scripting (XSS)

P5 FNIP-8x16A/FNIP-4xSH versions 1.0.20 and 1.0.11 suffer from a stored cross-site scripting vulnerability. Input passed to several GET/POST parameters is not properly sanitized before being returned to the user, allowing attackers to execute arbitrary HTML and script code in a user's browser sessi…

📅 Published: Feb. 5, 2026, 4:14 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-37152 - PHP-Fusion 9.03.50 panels.php - Cross-Site Scripting (XSS)

PHP-Fusion 9.03.50 panels.php is vulnerable to cross-site scripting (XSS) via the 'panel_content' POST parameter. The application fails to properly sanitize user input before rendering it in the browser, allowing attackers to inject arbitrary JavaScript. This can be exploited by submitting crafted …

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: March 5, 2026, 1:28 a.m.

8.7

CVSS4.0

CVE-2020-37150 - Edimax Technology EW-7438RPn-v3 Mini 1.27 - Unauthorized Access: Wi-Fi Password Disclosure

Edimax EW-7438RPn-v3 Mini 1.27 allows unauthenticated attackers to access the /wizard_reboot.asp page in unsetup mode, which discloses the Wi-Fi SSID and security key. Attackers can retrieve the wireless password by sending a GET request to this endpoint, exposing sensitive information without auth…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: March 5, 2026, 1:28 a.m.

5.1

CVSS4.0

CVE-2020-37149 - Edimax Technology EW-7438RPn-v3 Mini 1.27 - Cross-Site Request Forgery (CSRF) to Command Execution

Edimax EW-7438RPn-v3 Mini 1.27 is vulnerable to cross-site request forgery (CSRF) that can lead to command execution. An attacker can trick an authenticated user into submitting a crafted form to the /goform/mp endpoint, resulting in arbitrary command execution on the device with the user's privile…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: March 5, 2026, 1:28 a.m.

5.1

CVSS4.0

CVE-2020-37145 - HRSALE 1.1.8 - Cross-Site Request Forgery (Add Admin)

HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user acco…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.1

CVSS4.0

CVE-2020-37144 - Exagate Sysguard 6001 - Cross-Site Request Forgery (Add Admin)

Exagate SYSGuard 6001 contains a cross-site request forgery vulnerability that allows attackers to create unauthorized admin accounts through a crafted HTML form. Attackers can trick users into submitting a malicious form to /kulyon.php that adds a new user with administrative privileges without th…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2020-37143 - ProficySCADA for iOS 5.0.25920 - 'Password' Denial of Service

ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful …

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.4

CVSS4.0

CVE-2020-37142 - 10-Strike Network Inventory Explorer 8.54 - 'Add' Local Buffer Overflow (SEH)

10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add' function to trigger…

📅 Published: Feb. 5, 2026, 4:13 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346543
Page 1522 of 34,655
« previous page » next page
Filters