|
196631
|
6.5 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware sd-wan_wanop
|
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10…
|
CWE-94
Code Injection
|
CVE-2020-8194
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196632
|
6.5 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware sd-wan_wanop
|
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.…
|
CWE-287
Improper Authentication
|
CVE-2020-8193
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196633
|
6.1 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware sd-wan_wanop
|
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 1…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8191
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196634
|
7.5 |
HIGH
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware
|
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-8190
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196635
|
7.5 |
HIGH
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware
|
Improper input validation in Citrix ADC and Citrix Gateway versions before 11.1-63.9 and 12.0-62.10 allows unauthenticated users to perform a denial of service attack.
|
CWE-20
Improper Input Validation
|
CVE-2020-8187
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196636
|
9.8 |
CRITICAL
Network
|
devcert_project
|
devcert
|
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
|
CWE-78
OS Command
|
CVE-2020-8186
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196637
|
4.3 |
MEDIUM
Network
|
nextcloud
|
contacts
|
A missing file type check in Nextcloud Contacts 3.2.0 allowed a malicious user to upload any file as avatars.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8181
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196638
|
9.8 |
CRITICAL
Network
|
phpzag
|
phpzag
|
SQL injection with start and length parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
|
CWE-89
SQL Injection
|
CVE-2020-8521
|
2024-11-21 14:38 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196639
|
9.8 |
CRITICAL
Network
|
phpzag
|
phpzag
|
SQL injection in order and column parameters in Records.php for phpzag live add edit delete data tables records with ajax php mysql
|
CWE-89
SQL Injection
|
CVE-2020-8520
|
2024-11-21 14:38 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196640
|
9.8 |
CRITICAL
Network
|
phpzag
|
phpzag
|
SQL injection with the search parameter in Records.php for phpzag live add edit delete data tables records with ajax php mysql
|
CWE-89
SQL Injection
|
CVE-2020-8519
|
2024-11-21 14:38 |
2020-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|