|
196641
|
8.8 |
HIGH
Network
|
ui
|
unifi_protect_firmware
|
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Pr…
|
CWE-78
OS Command
|
CVE-2020-8188
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196642
|
6.5 |
MEDIUM
Network
|
rubyonrails fedoraproject
|
rails fedora
|
A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-8185
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196643
|
4.1 |
MEDIUM
Network
|
nextcloud
|
deck
|
Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks.
|
CWE-269
Improper Privilege Management
|
CVE-2020-8179
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196644
|
6.1 |
MEDIUM
Network
|
shopify
|
koa-shopify-auth
|
A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the `shop` parameter on the `/shopify/auth/enable_cookies` endpoint.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8176
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196645
|
4.3 |
MEDIUM
Network
|
rubyonrails debian
|
rails debian_linux
|
A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, fo…
|
CWE-352
Origin Validation Error
|
CVE-2020-8166
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196646
|
8.8 |
HIGH
Network
|
rubyonrails debian
|
rails debian_linux
|
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
|
CWE-94
Code Injection
|
CVE-2020-8163
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196647
|
8.6 |
HIGH
Network
|
rack_project debian canonical
|
rack debian_linux ubuntu_linux
|
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in…
|
CWE-22
Path Traversal
|
CVE-2020-8161
|
2024-11-21 14:38 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196648
|
7.8 |
HIGH
Local
|
oneidentity
|
syslog-ng
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of syslog-ng of SUSE Linux Enterprise Debuginfo 11-SP3, SUSE Linux Enterprise Debuginfo 11-SP4, SUSE Linux Enterprise Module fo…
|
-
|
CVE-2020-8019
|
2024-11-21 14:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196649
|
7.8 |
HIGH
Local
|
opensuse
|
leap tumbleweed_kopano-spamd
|
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to es…
|
-
|
CVE-2020-8014
|
2024-11-21 14:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196650
|
5.3 |
MEDIUM
Local
|
opensuse
|
hylafax\+
|
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calli…
|
-
|
CVE-2020-8024
|
2024-11-21 14:38 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|