|
197821
|
7.2 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
|
CWE-94
Code Injection
|
CVE-2020-8218
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197822
|
5.4 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8217
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197823
|
4.3 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.
|
NVD-CWE-noinfo
|
CVE-2020-8216
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197824
|
5.3 |
MEDIUM
Network
|
ui
|
unifi_protect
|
An information exposure vulnerability exists in UniFi Protect before v1.13.4-beta.5 that allowed unauthenticated attackers access to valid usernames for the UniFi Protect web application via HTTP res…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2020-8213
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197825
|
8.1 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.
|
CWE-287
Improper Authentication
|
CVE-2020-8206
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197826
|
6.1 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8204
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197827
|
5.3 |
MEDIUM
Network
|
nextcloud
|
preferred_providers
|
Improper check of inputs in Nextcloud Preferred Providers app v1.6.0 allowed to perform a denial of service attack when using a very long password.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-8202
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197828
|
6.5 |
MEDIUM
Network
|
fastify
|
fastify
|
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted sche…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8192
|
2024-11-21 14:38 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197829
|
8.8 |
HIGH
Network
|
citrix
|
workspace
|
Improper access control in Citrix Workspace app for Windows 1912 CU1 and 2006.1 causes privilege escalation and code execution when the automatic updater service is running.
|
CWE-287
Improper Authentication
|
CVE-2020-8207
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197830
|
5.5 |
MEDIUM
Local
|
jpeg-js_project
|
jpeg-js
|
Uncontrolled resource consumption in `jpeg-js` before 0.4.0 may allow attacker to launch denial of service attacks using specially a crafted JPEG image.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8175
|
2024-11-21 14:38 |
2020-07-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|