The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2020-35666 - Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 v... read CVE-2020-35666
    Published: December 23, 2020; 3:15:12 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.5 MEDIUM

  • CVE-2020-35665 - An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in the Event parameter in include/makecvs.php during CSV creation.
    Published: December 23, 2020; 3:15:12 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2020-29551 - An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is possible to shutdown the system. Among others, the following files and scripts are also accessible: _internal/pc/abort.php, _internal/pc/restart.php,... read CVE-2020-29551
    Published: December 23, 2020; 11:15:12 AM -0500

    V3.1: 9.1 CRITICAL
    V2.0: 8.5 HIGH

  • CVE-2020-35276 - EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
    Published: December 21, 2020; 10:15:13 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2020-35252 - Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
    Published: December 23, 2020; 2:15:13 PM -0500

    V3.1: 6.1 MEDIUM
    V2.0: 4.3 MEDIUM

  • CVE-2020-29583 - Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh ser... read CVE-2020-29583
    Published: December 22, 2020; 5:15:14 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 2.1 LOW

  • CVE-2020-11719 - An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. It relies on broken encryption with a weak and guessable static encryption key.
    Published: December 23, 2020; 12:15:12 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2018-1000892 - Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.
    Published: December 23, 2020; 12:15:12 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2018-1000891 - Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.
    Published: December 23, 2020; 12:15:12 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-11718 - An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and below. Its software-update packages are downloaded via cleartext HTTP.
    Published: December 23, 2020; 11:15:12 AM -0500

    V3.1: 7.4 HIGH
    V2.0: 5.8 MEDIUM

  • CVE-2020-11720 - An issue was discovered in Programi Bilanc build 007 release 014 31.01.2020 and possibly below. During the installation, it sets up administrative access by default with the account admin and password 0000. After the installation, users/admins are... read CVE-2020-11720
    Published: December 23, 2020; 11:15:12 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2020-29550 - An issue was discovered in URVE Build 24.03.2020. The password of an integration user account (used for the connection of the MS Office 365 Integration Service) is stored in cleartext in configuration files as well as in the database. The followin... read CVE-2020-29550
    Published: December 23, 2020; 11:15:12 AM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-29552 - An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0%3bpowershell+-c+" substring, it is possible to execute a Powershell command and redirect its output to a file under the web root.
    Published: December 23, 2020; 11:15:12 AM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 10.0 HIGH

  • CVE-2020-35269 - There is a Cross Site Request Forgery (CSRF) vulnerability in Nagios Core 4.2.4.
    Published: December 23, 2020; 2:15:13 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2020-35598 - ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI.
    Published: December 23, 2020; 2:15:13 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-28071 - SourceCodester Alumni Management System 1.0 is affected by cross-site Scripting (XSS) in /admin/gallery.php. After the admin authentication an attacker can upload an image in the gallery using a XSS payload in the description textarea called 'abou... read CVE-2020-28071
    Published: December 23, 2020; 1:15:12 PM -0500

    V3.1: 4.8 MEDIUM
    V2.0: 3.5 LOW

  • CVE-2020-35370 - A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specific shell... read CVE-2020-35370
    Published: December 23, 2020; 2:15:13 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 9.3 HIGH

  • CVE-2020-28070 - SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
    Published: December 23, 2020; 1:15:12 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2018-1000893 - Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.
    Published: December 23, 2020; 12:15:12 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2020-35587 - ** DISPUTED ** In Solstice Pod before 3.0.3, the firmware can easily be decompiled/disassembled. The decompiled/disassembled files contain non-obfuscated code. NOTE: it is unclear whether lack of obfuscation is directly associated with a negative ... read CVE-2020-35587
    Published: December 23, 2020; 11:15:12 AM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM