|
195991
|
4.9 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure
|
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Enti…
|
CWE-611
XXE
|
CVE-2020-8256
|
2024-11-21 14:38 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195992
|
7.2 |
HIGH
Network
|
pulsesecure ivanti
|
pulse_connect_secure pulse_policy_secure policy_secure connect_secure
|
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
|
CWE-94
Code Injection
|
CVE-2020-8243
|
2024-11-21 14:38 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195993
|
6.1 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure pulse_policy_secure policy_secure connect_secure
|
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
|
CWE-79
Cross-site Scripting
|
CVE-2020-8238
|
2024-11-21 14:38 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195994
|
6.1 |
MEDIUM
Network
|
lenovo
|
enterprise_network_disk
|
A DOM-based cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user's…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8348
|
2024-11-21 14:38 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195995
|
6.1 |
MEDIUM
Network
|
lenovo
|
enterprise_network_disk
|
A reflective cross-site scripting (XSS) vulnerability was reported in Lenovo Enterprise Network Disk prior to version 6.1 patch 6 hotfix 4 that could allow execution of code in an authenticated user'…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8347
|
2024-11-21 14:38 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195996
|
7.8 |
HIGH
Local
|
lenovo
|
63_firmware h50-30g_firmware m4500_firmware m4550_firmware qitian_4500_firmware qitian_b4550_firmware qitian_m4550_firmware thinkcentre_e73_firmware thinkcentre_e73s_firmware<…
|
A potential vulnerability in the SMI callback function used in the EEPROM driver in some Lenovo Desktops and ThinkStation models may allow arbitrary code execution
|
NVD-CWE-noinfo
|
CVE-2020-8333
|
2024-11-21 14:38 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195997
|
7.5 |
HIGH
Network
|
citrix
|
xenmobile_server
|
Improper authentication in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix XenMobile Server 10.10 before RP6 and Citrix XenMobile Server before 10.9 RP5 lea…
|
CWE-287
Improper Authentication
|
CVE-2020-8253
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195998
|
7.8 |
HIGH
Local
|
nodejs opensuse fedoraproject
|
node.js leap fedora
|
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is lon…
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-8252
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195999
|
7.5 |
HIGH
Network
|
nodejs fedoraproject
|
node.js fedora
|
Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8251
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196000
|
8.8 |
HIGH
Network
|
citrix
|
application_delivery_controller_firmware gateway netscaler_gateway sd-wan_wanop
|
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix A…
|
CWE-269
Improper Privilege Management
|
CVE-2020-8247
|
2024-11-21 14:38 |
2020-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|