CVE Monitor

Monitor de vulnerabilidades: 2,030 registros - Actualizado: 26/01/2026 16:04:41

Página 9 de 170 Actualizar Datos
CVE-2020-36914 CVSS: 7.5
QiHang Media Web Digital Signage 3.0.9 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept user authentication credentials through cleartext cookie transmission. Attackers can perform man-in-the-middle attacks to capture and potentially misuse stored authentication credentials transmitted in an insecure manner.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36915 CVSS: 7.5
Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product versions.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36916 CVSS: 8.8
TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36917 CVSS: 7.5
iDS6 DSSPro Digital Signage System 6.2 contains a sensitive information disclosure vulnerability that allows remote attackers to intercept authentication credentials through cleartext cookie transmission. Attackers can exploit the autoSave feature to capture user passwords during man-in-the-middle attacks on HTTP communications.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36906 CVSS: 4.3
P5 FNIP-8x16A FNIP-4xSH 1.0.20 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages to add new admin users, change passwords, and modify system configurations by tricking authenticated users into loading a specially crafted form.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36907 CVSS: 7.5
Aerohive HiveOS contains a denial of service vulnerability in the NetConfig UI that allows unauthenticated attackers to render the web interface unusable. Attackers can send a crafted HTTP request to the action.php5 script with specific parameters to trigger a 5-minute service disruption.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36908 CVSS: 5.3
SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft a malicious web page that automatically submits a form to create a new super user account with full administrative privileges when a logged-in user visits the page.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36909 CVSS: 6.5
SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI script. Attackers can manipulate POST request parameters in /cgi-bin/cgix/edit_config_files to access and modify files outside the intended /etc/config/ directory.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36910 CVSS: 8.8
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.
06 Jan 2026
disclosure@vulncheck.com
CVE-2020-36905 CVSS: 7.5
FIBARO System Home Center 5.021 contains a remote file inclusion vulnerability in the undocumented proxy API that allows attackers to include arbitrary client-side scripts. Attackers can exploit the 'url' GET parameter to inject malicious JavaScript and potentially hijack user sessions or manipulate page content.
06 Jan 2026
disclosure@vulncheck.com
CVE-2025-46696 CVSS: 6.4
Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
06 Jan 2026
security_alert@emc.com
CVE-2026-21493 CVSS: 6.6
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1.1 and below are vulnerable to Type Confusion in its CIccSingleSampledeCurveXml class during XML Curve Serialization. This issue is fixed in version 2.3.1.2.
06 Jan 2026
security-advisories@github.com
Página 9 de 170