|
196611
|
5.3 |
MEDIUM
Network
|
ui
|
unifi_protect
|
An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP res…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-8213
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196612
|
8.1 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.
|
CWE-287
Improper Authentication
|
CVE-2020-8206
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196613
|
6.1 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8204
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196614
|
5.3 |
MEDIUM
Network
|
nextcloud
|
preferred_providers
|
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-8202
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196615
|
6.5 |
MEDIUM
Network
|
fastify
|
fastify
|
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted sche…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8192
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196616
|
8.8 |
HIGH
Network
|
citrix
|
workspace
|
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.
|
CWE-287
Improper Authentication
|
CVE-2020-8207
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196617
|
5.5 |
MEDIUM
Local
|
jpeg-js_project
|
jpeg-js
|
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8175
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196618
|
8.1 |
HIGH
Network
|
nodejs oracle netapp
|
node.js banking_extensibility_workbench retail_xstore_point_of_service mysql_cluster blockchain_platform snapcenter oncommand_workflow_automation oncommand_insight active_iq_u…
|
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-8174
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196619
|
7.8 |
HIGH
Local
|
lenovo
|
drivers_management
|
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-8326
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196620
|
7.8 |
HIGH
Local
|
lenovo
|
drivers_management
|
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges.
|
CWE-426
Untrusted Search Path
|
CVE-2020-8317
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|