|
210051
|
8.8 |
HIGH
Network
|
webtoffee
|
import_export_wordpress_users
|
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
|
CWE-269
Improper Privilege Management
|
CVE-2020-12074
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210052
|
8.8 |
HIGH
Network
|
cyberchimps
|
gutenberg_\&_elementor_templates_importer_for_responsive
|
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
|
NVD-CWE-Other
|
CVE-2020-12073
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210053
|
4.8 |
MEDIUM
Network
|
anchorcms
|
anchor
|
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12071
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210054
|
7.5 |
HIGH
Network
|
teeworlds opensuse fedoraproject debian canonical
|
teeworlds leap backports_sle fedora debian_linux ubuntu_linux
|
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
|
CWE-20
Improper Input Validation
|
CVE-2020-12066
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210055
|
7.5 |
HIGH
Network
|
linuxfoundation canonical
|
ceph ubuntu_linux
|
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12059
|
2024-11-21 13:59 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210056
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In oth…
|
NVD-CWE-noinfo
|
CVE-2020-12051
|
2024-11-21 13:59 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210057
|
7.5 |
HIGH
Network
|
evenroute
|
iqrouter_firmware
|
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new ne…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-11968
|
2024-11-21 13:59 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210058
|
9.8 |
CRITICAL
Network
|
evenroute
|
iqrouter_firmware
|
In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can o…
|
CWE-862
Missing Authorization
|
CVE-2020-11967
|
2024-11-21 13:59 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210059
|
9.8 |
CRITICAL
Network
|
evenroute
|
iqrouter_firmware
|
In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only o…
|
CWE-521
Weak Password Requirements
|
CVE-2020-11966
|
2024-11-21 13:59 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210060
|
9.8 |
CRITICAL
Network
|
evenroute
|
iqrouter_firmware
|
In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a bran…
|
CWE-287
Improper Authentication
|
CVE-2020-11965
|
2024-11-21 13:59 |
2020-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|