|
214531
|
10.0 |
CRITICAL
Network
|
wpewebkit webkitgtk fedoraproject debian canonical opensuse
|
wpe_webkit webkitgtk fedora debian_linux ubuntu_linux leap
|
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-des…
|
CWE-20
Improper Input Validation
|
CVE-2020-13753
|
2024-11-21 14:01 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214532
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's prof…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13653
|
2024-11-21 14:01 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214533
|
9.8 |
CRITICAL
Network
|
locutus
|
locutus_php
|
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
|
CWE-78
OS Command
|
CVE-2020-13619
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214534
|
7.5 |
HIGH
Network
|
os4ed
|
opensis
|
openSIS through 7.4 allows Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-13383
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214535
|
9.1 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS through 7.4 has Incorrect Access Control.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13382
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214536
|
9.8 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS through 7.4 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-13381
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214537
|
9.8 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS before 7.4 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-13380
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214538
|
5.5 |
MEDIUM
Local
|
avast
|
avg_antivirus free_antivirus
|
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control o…
|
NVD-CWE-noinfo
|
CVE-2020-13657
|
2024-11-21 14:01 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214539
|
4.8 |
MEDIUM
Network
|
form_builder_for_magento_2_project
|
form_builder_for_magento_2
|
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13423
|
2024-11-21 14:01 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214540
|
7.5 |
HIGH
Network
|
acf_to_rest_api_project
|
acf_to_rest_api
|
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/optio…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-13700
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|