|
208201
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. If TslAlloc attempts to allocate thread local storage but obtains an unacceptable index value, V8 throws an exception that leads to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-26535
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208202
|
9.8 |
CRITICAL
Network
|
foxitsoftware
|
foxit_reader phantompdf
|
An issue was discovered in Foxit Reader and PhantomPDF before 10.1. There is an Opt object use-after-free related to Field::ClearItems and Field::DeleteOptions, during AcroForm JavaScript execution.
|
CWE-416
Use After Free
|
CVE-2020-26534
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208203
|
5.3 |
MEDIUM
Network
|
filecloud
|
filecloud
|
CodeLathe FileCloud before 20.2.0.11915 allows username enumeration.
|
NVD-CWE-noinfo
|
CVE-2020-26524
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208204
|
6.1 |
MEDIUM
Network
|
froala
|
froala_editor
|
Froala Editor before 3.2.2 allows XSS via pasted content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-26523
|
2024-11-21 14:20 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208205
|
- |
|
-
|
-
|
Dotmesh is a git-like command-line interface for capturing, organizing and sharing application states. In versions 0.8.1 and prior, the unsafe handling of symbolic links in an unpacking routine may
…
|
-
|
CVE-2020-26312
|
2024-11-21 14:19 |
2024-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208206
|
9.8 |
CRITICAL
Network
|
evenbalance
|
punkbuster
|
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
|
CWE-22
Path Traversal
|
CVE-2020-26037
|
2024-11-21 14:19 |
2023-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208207
|
5.3 |
MEDIUM
Network
|
cisco
|
asyncos
|
A vulnerability in the zip decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass content filters that are c…
|
NVD-CWE-noinfo
|
CVE-2020-26082
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208208
|
6.5 |
MEDIUM
Network
|
cisco
|
catalyst_sd-wan_manager
|
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensit…
|
CWE-22
Path Traversal
|
CVE-2020-26065
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208209
|
8.1 |
HIGH
Network
|
cisco
|
catalyst_sd-wan_manager
|
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system.
The v…
|
CWE-611
XXE
|
CVE-2020-26064
|
2024-11-21 14:19 |
2023-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208210
|
9.8 |
CRITICAL
Network
|
gnuplot_project
|
gnuplot
|
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
|
CWE-120
Classic Buffer Overflow
|
CVE-2020-25969
|
2024-11-21 14:19 |
2023-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|