Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2020-12145EPSS 6%
Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+ uses HTTP headers to authenticate REST API calls from localhost. This m…
Unity Orchestrator
8.9.11 / 8.10.11+
HIGH 8.8
CVE-2020-12146EPSS 28%
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted fil…
Unity Orchestrator
8.9.11 / 8.10.11+
HIGH 8.8
CVE-2020-12147
In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can make unauthorized MySQL queries against t…
Unity Orchestrator
8.9.11 / 8.10.11+
HIGH 7.2
CVE-2019-16103
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows privilege escalation (by administrators) from the menu to a root Bash OS shell via the spsshell …
Unity Edgeconnect Sd Wan Firmware
No fix yet
MEDIUM 6.1
CVE-2019-16104
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATH_INFO.
Unity Edgeconnect Sd Wan Firmware
No fix yet
CRITICAL 9.8
CVE-2019-16102
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has an SNMP service with a public value for rocommunity and trapcommunity.
Unity Edgeconnect Sd Wan Firmware
Mitigation only
HIGH 8.8
CVE-2019-16099
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows CSRF via JSON data to a .swf file.
Unity Edgeconnect Sd Wan Firmware
No fix yet
HIGH 7.5
CVE-2019-16100
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to trigger a web-interface outage via slow client-side HTTP traffic from a sing…
Unity Edgeconnect Sd Wan Firmware
No fix yet
MEDIUM 5.3
CVE-2019-16101
Silver Peak EdgeConnect SD-WAN before 8.1.7.x allows remote attackers to obtain potentially sensitive stack traces by sending incorrect JSON data to …
Unity Edgeconnect Sd Wan Firmware
Mitigation only
MEDIUM 6.8
CVE-2014-2974
Cross-site request forgery (CSRF) vulnerability in php/user_account.php in Silver Peak VX through 6.2.4 allows remote attackers to hijack the authent…
Vx
after 6.2.4