|
197611
|
8.1 |
HIGH
Network
|
nodejs debian fedoraproject oracle siemens
|
node.js debian_linux fedora graalvm sinec_infrastructure_network_services
|
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::T…
|
CWE-416
Use After Free
|
CVE-2020-8265
|
2024-11-21 14:38 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197612
|
6.1 |
MEDIUM
Network
|
mendix
|
mendixsso
|
MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supp…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8160
|
2024-11-21 14:38 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197613
|
7.8 |
HIGH
Local
|
backblaze
|
backblaze
|
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of cl…
|
CWE-269
Improper Privilege Management
|
CVE-2020-8290
|
2024-11-21 14:38 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197614
|
7.8 |
HIGH
Local
|
backblaze
|
backblaze
|
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where …
|
CWE-295
Improper Certificate Validation
|
CVE-2020-8289
|
2024-11-21 14:38 |
2020-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197615
|
9.8 |
CRITICAL
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execut…
|
CWE-78
OS Command
|
CVE-2020-8466
|
2024-11-21 14:38 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197616
|
9.8 |
CRITICAL
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authenticat…
|
CWE-287 CWE-352
Improper Authentication Origin Validation Error
|
CVE-2020-8465
|
2024-11-21 14:38 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197617
|
7.5 |
HIGH
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to send requests that appear to come from the localhost which could expose the product's admin …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8464
|
2024-11-21 14:38 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197618
|
7.5 |
HIGH
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to bypass a global authorization check for anonymous users by manipulating request paths.
|
CWE-22
Path Traversal
|
CVE-2020-8463
|
2024-11-21 14:38 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197619
|
4.8 |
MEDIUM
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamper with the web interface of the product.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8462
|
2024-11-21 14:38 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197620
|
8.8 |
HIGH
Network
|
trendmicro
|
interscan_web_security_virtual_appliance
|
A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victim's browser to send a specifically encoded request without…
|
CWE-352
Origin Validation Error
|
CVE-2020-8461
|
2024-11-21 14:38 |
2020-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|