|
196021
|
5.4 |
MEDIUM
Network
|
nextcloud
|
desktop
|
A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8189
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196022
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue aff…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-7923
|
2024-11-21 14:38 |
2020-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196023
|
8.8 |
HIGH
Network
|
ui opensuse
|
edgeswitch_firmware leap backports_sle
|
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to esca…
|
CWE-78
OS Command
|
CVE-2020-8233
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196024
|
6.5 |
MEDIUM
Network
|
ui
|
edgeswitch_firmware
|
An information disclosure vulnerability exists in EdgeMax EdgeSwitch firmware v1.9.0 that allowed read only users could obtain unauthorized information through SNMP community pages.
|
CWE-200
Information Exposure
|
CVE-2020-8232
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196025
|
5.5 |
MEDIUM
Local
|
nextcloud
|
desktop
|
A memory corruption vulnerability exists in NextCloud Desktop Client v2.6.4 where missing ASLR and DEP protections in for windows allowed to corrupt memory.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-8230
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196026
|
5.8 |
MEDIUM
Network
|
phpbb
|
phpbb
|
A vulnerability exists in phpBB <v3.2.10 and <v3.3.1 which allowed remote image dimensions check to be used to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8226
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196027
|
9.8 |
CRITICAL
Network
|
citrix
|
xenmobile_server
|
Improper access control in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows acc…
|
CWE-863
Incorrect Authorization
|
CVE-2020-8212
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196028
|
9.8 |
CRITICAL
Network
|
citrix
|
xenmobile_server
|
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows S…
|
CWE-89
SQL Injection
|
CVE-2020-8211
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196029
|
7.5 |
HIGH
Network
|
citrix
|
xenmobile_server
|
Insufficient protection of secrets in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2020-8210
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196030
|
7.5 |
HIGH
Network
|
citrix
|
xenmobile_server
|
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 and…
|
CWE-22
Path Traversal
|
CVE-2020-8209
|
2024-11-21 14:38 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|