CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-7174

    Last Modified: 21 Nov 2024

    A soapconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    8.8
    High

    CVE-2020-7173

    Last Modified: 21 Nov 2024

    A actionselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7172

    Last Modified: 21 Nov 2024

    A templateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7171

    Last Modified: 21 Nov 2024

    A guidatadetail expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7170

    Last Modified: 21 Nov 2024

    A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7169

    Last Modified: 21 Nov 2024

    A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7168

    Last Modified: 21 Nov 2024

    A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7167

    Last Modified: 21 Nov 2024

    A quicktemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7166

    Last Modified: 21 Nov 2024

    A operatorgrouptreeselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7165

    Last Modified: 21 Nov 2024

    A iccselectcommand expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7164

    Last Modified: 21 Nov 2024

    A operationselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7163

    Last Modified: 21 Nov 2024

    A navigationto expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7162

    Last Modified: 21 Nov 2024

    A operatorgroupselectcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7161

    Last Modified: 21 Nov 2024

    A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7160

    Last Modified: 21 Nov 2024

    A iccselectdeviceseries expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7159

    Last Modified: 21 Nov 2024

    A customtemplateselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7158

    Last Modified: 21 Nov 2024

    A perfselecttask expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7157

    Last Modified: 21 Nov 2024

    A selviewnavcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7156

    Last Modified: 21 Nov 2024

    A faultinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7155

    Last Modified: 21 Nov 2024

    A select expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7154

    Last Modified: 21 Nov 2024

    A ifviewselectpage expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7153

    Last Modified: 21 Nov 2024

    A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7152

    Last Modified: 21 Nov 2024

    A faultparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7151

    Last Modified: 21 Nov 2024

    A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7150

    Last Modified: 21 Nov 2024

    A faultstatchoosefaulttype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7149

    Last Modified: 21 Nov 2024

    A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7148

    Last Modified: 21 Nov 2024

    A deployselectsoftware expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7147

    Last Modified: 21 Nov 2024

    A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7146

    Last Modified: 21 Nov 2024

    A devgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7145

    Last Modified: 21 Nov 2024

    A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7144

    Last Modified: 21 Nov 2024

    A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7143

    Last Modified: 21 Nov 2024

    A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7142

    Last Modified: 21 Nov 2024

    A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-7141

    Last Modified: 21 Nov 2024

    A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24652

    Last Modified: 21 Nov 2024

    A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24651

    Last Modified: 21 Nov 2024

    A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24650

    Last Modified: 21 Nov 2024

    A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24649

    Last Modified: 21 Nov 2024

    A remote bytemessageresource transformentity" input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24648

    Last Modified: 21 Nov 2024

    A accessmgrservlet classname deserialization of untrusted data remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24647

    Last Modified: 21 Nov 2024

    A remote accessmgrservlet classname input validation code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24646

    Last Modified: 21 Nov 2024

    A tftpserver stack-based buffer overflow remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    8.8
    High

    CVE-2020-24630

    Last Modified: 21 Nov 2024

    A remote operatoronlinelist_content privilege escalation vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    9.8
    Critical

    CVE-2020-24629

    Last Modified: 21 Nov 2024

    A remote urlaccesscontroller authentication bypass vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).

    Published: 19 Oct 2020
    6.1
    Medium

    CVE-2020-26891

    Last Modified: 21 Nov 2024

    AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/*/fallback/web or /_matrix/client/unstable/auth/*/fallback/web Synapse endpoints.

    Published: 19 Oct 2020
    7.5
    High

    CVE-2020-24266

    Last Modified: 21 Nov 2024

    An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service.

    Published: 19 Oct 2020
    7.5
    High

    CVE-2020-24265

    Last Modified: 21 Nov 2024

    An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.

    Published: 19 Oct 2020
    8.8
    High

    CVE-2020-15909

    Last Modified: 21 Nov 2024

    SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against multiple sources such as sourceip, MFA claim, etc. as long as the victim stays logged in within N-Central. To take advantage of this, cookie could be stolen and the JSESSIONID can be captured. On its own this is not a surprising result; low security tools allow the cookie to roam from machine to machine. The JSESSION cookie can then be used on the attackers’ workstation by browsing to the victim’s NCentral server URL and replacing the JSESSIONID attribute value by the captured value. Expected behavior would be to check this against a second source and enforce at least a reauthentication or multi factor request as N-Central is a highly privileged service.

    Published: 19 Oct 2020
    4.7
    Medium

    CVE-2020-15910

    Last Modified: 21 Nov 2024

    SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker.

    Published: 19 Oct 2020
    8.8
    High

    CVE-2020-13778

    Last Modified: 21 Nov 2024

    rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.

    Published: 19 Oct 2020
    5.3
    Medium

    CVE-2020-8929

    Last Modified: 5 Jun 2025

    A mis-handling of invalid unicode characters in the Java implementation of Tink versions prior to 1.5 allows an attacker to change the ID part of a ciphertext, which result in the creation of a second ciphertext that can decrypt to the same plaintext. This can be a problem with encrypting deterministic AEAD with a single key, and rely on a unique ciphertext-per-plaintext.

    Published: 19 Oct 2020