|
196621
|
7.5 |
HIGH
Network
|
servey_project
|
servey
|
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
|
CWE-22
Path Traversal
|
CVE-2020-8214
|
2024-11-21 14:38 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196622
|
8.8 |
HIGH
Network
|
automattic
|
canvas
|
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-8215
|
2024-11-21 14:38 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196623
|
7.5 |
HIGH
Network
|
transloadit
|
uppy
|
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interac…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-8205
|
2024-11-21 14:38 |
2020-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196624
|
9.8 |
CRITICAL
Network
|
jison_project
|
jison
|
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
|
CWE-78
OS Command
|
CVE-2020-8178
|
2024-11-21 14:38 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196625
|
7.4 |
HIGH
Network
|
lodash oracle
|
lodash peoplesoft_enterprise_peopletools communications_billing_and_revenue_management enterprise_communications_broker banking_extensibility_workbench banking_virtual_account_manageme…
|
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-8203
|
2024-11-21 14:38 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196626
|
7.8 |
HIGH
Local
|
citrix
|
gateway_plug-in_for_linux
|
Improper access control in Citrix ADC Gateway Linux client versions before 1.0.0.137 results in local privilege escalation to root.
|
NVD-CWE-noinfo
|
CVE-2020-8199
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196627
|
6.1 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware sd-wan_wanop
|
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 1…
|
CWE-79
Cross-site Scripting
|
CVE-2020-8198
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196628
|
8.8 |
HIGH
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware
|
Privilege escalation vulnerability on Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows a low privileged user with management access t…
|
NVD-CWE-noinfo
|
CVE-2020-8197
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196629
|
4.3 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware sd-wan_wanop
|
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.…
|
CWE-287
Improper Authentication
|
CVE-2020-8196
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196630
|
6.5 |
MEDIUM
Network
|
citrix
|
application_delivery_controller_firmware netscaler_gateway_firmware gateway_firmware sd-wan_wanop gateway_plug-in_for_linux
|
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 1…
|
CWE-22
Path Traversal
|
CVE-2020-8195
|
2024-11-21 14:38 |
2020-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|