|
210041
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mec…
|
CWE-668 CWE-276
Exposure of Resource to Wrong Sphere Incorrect Default Permissions
|
CVE-2020-13240
|
2024-11-21 14:00 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr_erp\/crm
|
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13239
|
2024-11-21 14:00 |
2020-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
6.5 |
MEDIUM
Network
|
cacti fedoraproject
|
cacti fedora
|
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
|
CWE-352
Origin Validation Error
|
CVE-2020-13231
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
4.3 |
MEDIUM
Network
|
cacti debian fedoraproject
|
cacti debian_linux fedora
|
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-13230
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
5.5 |
MEDIUM
Local
|
kde
|
amarok
|
A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste resources over time,…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2020-13152
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
9.8 |
CRITICAL
Network
|
smartbear
|
readyapi
|
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into th…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-12835
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
9.8 |
CRITICAL
Network
|
wso2
|
api_manager
|
WSO2 API Manager 3.0.0 does not properly restrict outbound network access from a Publisher node, opening up the possibility of SSRF to this node's entire intranet.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13226
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
4.8 |
MEDIUM
Network
|
phpipam
|
phpipam
|
phpIPAM 1.4 contains a stored cross site scripting (XSS) vulnerability within the Edit User Instructions field of the User Instructions widget.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13225
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
7.5 |
HIGH
Network
|
wireshark debian opensuse fedoraproject
|
wireshark debian_linux leap fedora
|
In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a c…
|
CWE-674
Uncontrolled Recursion
|
CVE-2020-13164
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
7.4 |
HIGH
Network
|
em-imap_project
|
em-imap
|
em-imap 0.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is no…
|
CWE-295
Improper Certificate Validation
|
CVE-2020-13163
|
2024-11-21 14:00 |
2020-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|