Latest CVE Feed
-
6.5
MEDIUMCVE-2020-8300
Citrix ADC and Citrix/NetScaler Gateway before 13.0-82.41, 12.1-62.23, 11.1-65.20 and Citrix ADC 12.1-FIPS before 12.1-55.238 suffer from improper access control allowing SAML authentication hijack through a phishing attack to steal a valid user session. ... Read more
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8299
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource c... Read more
- Published: Jun. 16, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8298
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.... Read more
Affected Products : fs-path- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8297
Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.... Read more
Affected Products : deck- Published: Feb. 23, 2021
- Modified: Nov. 21, 2024
-
6.7
MEDIUMCVE-2020-8296
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.... Read more
- Published: Mar. 03, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8295
A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.... Read more
Affected Products : nextcloud_server- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8294
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.... Read more
Affected Products : nextcloud_server- Published: Feb. 03, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8293
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.... Read more
Affected Products : nextcloud_server- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8292
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.... Read more
Affected Products : rocket.chat- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2020-8291
A link preview rendering issue in Rocket.Chat versions before 3.9 could lead to potential XSS attacks.... Read more
Affected Products : rocket.chat- Published: Oct. 18, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2020-8290
Backblaze for Windows and Backblaze for macOS before 7.0.0.439 suffer from improper privilege management in `bztransmit` helper due to lack of permission handling and validation before creation of client update directories allowing for local escalation of... Read more
Affected Products : backblaze- Published: Dec. 27, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-8289
Backblaze for Windows before 7.0.1.433 and Backblaze for macOS before 7.0.1.434 suffer from improper certificate validation in `bztransmit` helper due to hardcoded whitelist of strings in URLs where validation is disabled leading to possible remote code e... Read more
Affected Products : backblaze- Published: Dec. 27, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8288
The `specializedRendering` function in Rocket.Chat server before 3.9.2 allows a cross-site scripting (XSS) vulnerability by way of the `value` parameter.... Read more
Affected Products : rocket.chat- Published: Jan. 26, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2020-8287
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can le... Read more
- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8286
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire peoplesoft_enterprise_peopletools macos clustered_data_ontap mac_os_x libcurl +11 more products- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2020-8285
curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire peoplesoft_enterprise_peopletools macos clustered_data_ontap mac_os_x libcurl +21 more products- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for ... Read more
Affected Products : fedora debian_linux curl hci_management_node solidfire peoplesoft_enterprise_peopletools macos clustered_data_ontap mac_os_x sinec_infrastructure_network_services +19 more products- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2020-8283
An authorised user on a Windows host running Citrix Universal Print Server can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285870 and CTX286120, 7.15 LTSR CU6 hotfix CTX285344 and 7.6 LTSR CU9.... Read more
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2020-8282
A security issue was found in EdgePower 24V/54V firmware v1.7.0 and earlier where, due to missing CSRF protections, an attacker would have been able to perform unauthorized remote code execution.... Read more
- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2020-8281
A missing file type check in Nextcloud Contacts 3.3.0 allows a malicious user to upload malicious SVG files to perform cross-site scripting (XSS) attacks.... Read more
Affected Products : contacts- Published: Jan. 06, 2021
- Modified: Nov. 21, 2024