CVE-2020-10987: Tenda AC1900 Router AC15 Model
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. Required action:…
Technology & Cybersecurity Intelligence
Curated security alerts, vulnerabilities, operating-system updates, cloud and AI news, and vendor advisories from trusted sources.
Tenda AC1900 Router AC15 Model contains an unspecified vulnerability that allows remote attackers to execute system commands via the deviceName POST parameter. Required action:…
VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to…
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request…
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker…
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.…
Zyxel firewalls (ATP, USG, VM) and AP Controllers (NXC2500 and NXC5500) contain a use of hard-coded credentials vulnerability in an undocumented account ("zyfwp") with…
Tenda AC11 devices contain a stack buffer overflow vulnerability in /goform/setmac which allows attackers to execute code via a crafted post request. Required action:…
VMware vCenter Server contains an information disclosure vulnerability in the VMware Directory Service (vmdir) when the Platform Services Controller (PSC) does not correctly implement…
Sonatype Nexus Repository contains an unspecified vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.…
SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API…
Zoho ManageEngine ServiceDesk Plus (SDP) contains an unspecified vulnerability that allows remote users to upload files via login page customization. Required action: Apply updates…
Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or…
VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute…
SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo. Required action: Apply updates per vendor instructions.
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path…
SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user…
Zoho ManageEngine Desktop Central contains a file upload vulnerability that allows for unauthenticated remote code execution. Required action: Apply updates per vendor instructions.