|
210871
|
7.2 |
HIGH
Network
|
mjml
|
mjml
|
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
|
CWE-22
Path Traversal
|
CVE-2020-12827
|
2024-11-21 14:00 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210872
|
8.8 |
HIGH
Network
|
tp-link
|
nc200_firmware nc210_firmware nc220_firmware nc230_firmware nc250_firmware nc260_firmware nc450_firmware
|
TP-LINK NC200 devices through 2.1.10 build 200401, NC210 devices through 1.0.10 build 200401, NC220 devices through 1.3.1 build 200401, NC230 devices through 1.3.1 build 200401, NC250 devices through…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-13224
|
2024-11-21 14:00 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210873
|
7.0 |
HIGH
Local
|
pulsesecure
|
pulse_secure_desktop_client pulse_secure_installer_service
|
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged …
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2020-13162
|
2024-11-21 14:00 |
2020-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210874
|
7.8 |
HIGH
Local
|
dlink
|
dsl-2750u_firmware
|
D-link DSL-2750U ISL2750UEME3.V1E devices allow approximately 90 seconds of access to the control panel, after a restart, before MAC address filtering rules become active.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13150
|
2024-11-21 14:00 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210875
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul and Consul Enterprise include an HTTP API (introduced in 1.2.0) and DNS (introduced in 1.4.3) caching feature that was vulnerable to denial of service. Fixed in 1.6.6 and 1.7.4.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2020-13250
|
2024-11-21 14:00 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210876
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul and Consul Enterprise did not appropriately enforce scope for local tokens issued by a primary data center, where replication to a secondary data center was not enabled. Introduced i…
|
CWE-20
Improper Input Validation
|
CVE-2020-13170
|
2024-11-21 14:00 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210877
|
5.3 |
MEDIUM
Network
|
hashicorp
|
consul
|
HashiCorp Consul and Consul Enterprise failed to enforce changes to legacy ACL token rules due to non-propagation to secondary data centers. Introduced in 1.4.0, fixed in 1.6.6 and 1.7.4.
|
NVD-CWE-noinfo
|
CVE-2020-12797
|
2024-11-21 14:00 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210878
|
7.5 |
HIGH
Network
|
hashicorp
|
consul
|
HashiCorp Consul and Consul Enterprise could crash when configured with an abnormally-formed service-router entry. Introduced in 1.6.0, fixed in 1.6.6 and 1.7.4.
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2020-12758
|
2024-11-21 14:00 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210879
|
7.2 |
HIGH
Network
|
redash
|
redash
|
Havoc Research discovered an authenticated Server-Side Request Forgery (SSRF) via the "JSON" data source of Redash open-source 8.0.0 and prior. Possibly, other connectors are affected. The SSRF is po…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-12725
|
2024-11-21 14:00 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210880
|
7.5 |
HIGH
Network
|
sos-berlin
|
jobscheduler
|
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored …
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-12712
|
2024-11-21 14:00 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|