
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-3548 | Published 2024-11-18 | CVSS: 5.3 | ShadowTrackr CVSS: 1.7 | Summary: A vulnerability in the Transport Layer Security (TLS) protocol implementation of Cisco AsyncOS software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause high CPU usage on an affected device, resulting in a denial of service (DoS) condition.
The vulnerability is due to inefficient processing of incoming TLS traffic. An attacker could exploit this vulnerability by sending a series of crafted TLS packets to an affected device. A successful exploit could allow the attacker to trigger a prolonged state of high CPU utilization. The affected device would still be operative, but response time and overall performance may be degraded.There are no workarounds that address this vulnerability. |
CVE: CVE-2020-35482 | Published 2021-02-03 | CVSS: 5.4 | ShadowTrackr CVSS: 0.4 | Summary: SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. |
CVE: CVE-2020-35481 | Published 2021-02-03 | CVSS: 9.8 | ShadowTrackr CVSS: 7.2 | Summary: SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. |
CVE: CVE-2020-35483 | Published 2021-01-11 | CVSS: 7.8 | ShadowTrackr CVSS: 4.0 | Summary: AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file. |
CVE: CVE-2020-35488 | Published 2021-01-05 | CVSS: 7.5 | ShadowTrackr CVSS: 6.9 | Summary: The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of service (daemon crash) via a crafted Syslog payload to the Syslog service. This attack requires a specific configuration. Also, the name of the directory created must use a Syslog field. (For example, on Linux it is not possible to create a .. directory. On Windows, it is not possible to create a CON directory.) |
CVE: CVE-2020-35480 | Published 2020-12-18 | CVSS: 5.3 | ShadowTrackr CVSS: 1.7 | Summary: An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code paths. |
CVE: CVE-2020-35489 | Published 2020-12-17 | CVSS: 10.0 | ShadowTrackr CVSS: 8.2 | Summary: The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters. |