|
209661
|
5.9 |
MEDIUM
Network
|
qore
|
qore
|
lib/QoreSocket.cpp in Qore before 0.9.4.2 lacks hostname verification for X.509 certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13615
|
2024-11-21 14:01 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209662
|
5.9 |
MEDIUM
Network
|
axel_project fedoraproject opensuse
|
axel fedora leap backports_sle
|
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13614
|
2024-11-21 14:01 |
2020-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209663
|
4.8 |
MEDIUM
Network
|
bbpress
|
bbpress
|
The bbPress plugin through 2.6.4 for WordPress has stored XSS in the Forum creation section, resulting in JavaScript execution at wp-admin/edit.php?post_type=forum (aka the Forum listing page) for al…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13487
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209664
|
6.1 |
MEDIUM
Network
|
verbb
|
knock_knock
|
The Knock Knock plugin before 1.2.8 for Craft CMS allows malicious redirection.
|
CWE-601
Open Redirect
|
CVE-2020-13486
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209665
|
9.1 |
CRITICAL
Network
|
verbb
|
knock_knock
|
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
|
CWE-697
Incorrect Comparison
|
CVE-2020-13485
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209666
|
7.4 |
HIGH
Network
|
em-http-request_project fedoraproject
|
em-http-request fedora
|
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certifi…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13482
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209667
|
5.4 |
MEDIUM
Network
|
verbb
|
image_resizer
|
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13459
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209668
|
8.8 |
HIGH
Network
|
verbb
|
image_resizer
|
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
|
CWE-352
Origin Validation Error
|
CVE-2020-13458
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209669
|
9.8 |
CRITICAL
Network
|
dext5
|
dext5
|
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13442
|
2024-11-21 14:01 |
2020-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209670
|
6.5 |
MEDIUM
Network
|
rockcarry
|
ffjpeg
|
ffjpeg through 2020-02-24 has an invalid write in bmp_load in bmp.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13440
|
2024-11-21 14:01 |
2020-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|