|
198321
|
2.2 |
LOW
Network
|
nextcloud
|
nextcloud_server
|
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2020-8173
|
2024-11-21 14:38 |
2020-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198322
|
5.4 |
MEDIUM
Network
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI file.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8263
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198323
|
6.1 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure pulse_policy_secure policy_secure connect_secure
|
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
|
CWE-79
Cross-site Scripting
|
CVE-2020-8262
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198324
|
4.3 |
MEDIUM
Network
|
pulsesecure ivanti
|
pulse_connect_secure pulse_policy_secure policy_secure connect_secure
|
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-8261
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198325
|
7.2 |
HIGH
Network
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-8260
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198326
|
4.9 |
MEDIUM
Network
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklist…
|
NVD-CWE-noinfo
|
CVE-2020-8255
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198327
|
8.8 |
HIGH
Network
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server. This vulnerability only affects Windows PDC.To i…
|
CWE-22
Path Traversal
|
CVE-2020-8254
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198328
|
7.8 |
HIGH
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
|
NVD-CWE-noinfo
|
CVE-2020-8250
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198329
|
7.8 |
HIGH
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-8249
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198330
|
7.8 |
HIGH
Local
|
pulsesecure
|
pulse_secure_desktop_client
|
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
|
NVD-CWE-noinfo
|
CVE-2020-8248
|
2024-11-21 14:38 |
2020-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|