|
196001
|
7.5 |
HIGH
Network
|
citrix
|
application_delivery_controller_firmware gateway netscaler_gateway sd-wan_wanop
|
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix A…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8246
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196002
|
7.5 |
HIGH
Network
|
json-bigint_project
|
json-bigint
|
Prototype pollution in json-bigint npm package < 1.0.0 may lead to a denial-of-service (DoS) attack.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8237
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196003
|
7.5 |
HIGH
Network
|
nextcloud
|
desktop
|
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-8225
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196004
|
7.4 |
HIGH
Network
|
nodejs opensuse fedoraproject
|
node.js leap fedora
|
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions,…
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-8201
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196005
|
6.5 |
MEDIUM
Network
|
citrix
|
storefront_server
|
Improper authentication in Citrix StoreFront Server < 1912.0.1000 allows an attacker who is authenticated on the same Microsoft Active Directory domain as a Citrix StoreFront server to read arbitrary…
|
CWE-287
Improper Authentication
|
CVE-2020-8200
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196006
|
6.1 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware gateway netscaler_gateway
|
Improper Input Validation on Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and Net…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8245
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196007
|
9.8 |
CRITICAL
Network
|
typeorm
|
typeorm
|
Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-8158
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196008
|
5.5 |
MEDIUM
Local
|
puppet
|
continuous_delivery
|
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-7945
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196009
|
9.3 |
CRITICAL
Local
|
suse
|
salt-netapi-client
|
A Improper Access Control vulnerability in the configuration of salt of SUSE Linux Enterprise Module for SUSE Manager Server 4.1, SUSE Manager Proxy 4.0, SUSE Manager Retail Branch Server 4.0, SUSE M…
|
-
|
CVE-2020-8028
|
2024-11-21 14:38 |
2020-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196010
|
5.5 |
MEDIUM
Local
|
lenovo
|
system_interface_foundation
|
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written t…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-8346
|
2024-11-21 14:38 |
2020-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|