|
209731
|
8.8 |
HIGH
Network
|
mappresspro
|
mappress
|
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12077
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209732
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
|
CWE-352
Origin Validation Error
|
CVE-2020-12076
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209733
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12075
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209734
|
8.8 |
HIGH
Network
|
webtoffee
|
import_export_wordpress_users
|
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
|
CWE-269
Improper Privilege Management
|
CVE-2020-12074
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209735
|
8.8 |
HIGH
Network
|
cyberchimps
|
gutenberg_\&_elementor_templates_importer_for_responsive
|
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
|
NVD-CWE-Other
|
CVE-2020-12073
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209736
|
4.8 |
MEDIUM
Network
|
anchorcms
|
anchor
|
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12071
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209737
|
7.5 |
HIGH
Network
|
teeworlds opensuse fedoraproject debian canonical
|
teeworlds leap backports_sle fedora debian_linux ubuntu_linux
|
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
|
CWE-20
Improper Input Validation
|
CVE-2020-12066
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209738
|
7.5 |
HIGH
Network
|
linuxfoundation canonical
|
ceph ubuntu_linux
|
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12059
|
2024-11-21 13:59 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209739
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In oth…
|
NVD-CWE-noinfo
|
CVE-2020-12051
|
2024-11-21 13:59 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209740
|
7.5 |
HIGH
Network
|
evenroute
|
iqrouter_firmware
|
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new ne…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-11968
|
2024-11-21 13:59 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|