|
210481
|
5.9 |
MEDIUM
Network
|
infradead opensuse
|
openconnect leap
|
OpenConnect through 8.08 mishandles negative return values from X509_check_ function calls, which might assist attackers in performing man-in-the-middle attacks.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2020-12105
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210482
|
6.1 |
MEDIUM
Network
|
catchplugins
|
catch_breadcrumb
|
The Catch Breadcrumb plugin before 1.5.4 for WordPress allows Reflected XSS via the s parameter (a search query). Also affected are 16 themes (if the plugin is enabled) by the same author: Alchemist …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12054
|
2024-11-21 13:59 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210483
|
10.0 |
CRITICAL
Network
|
beakerbrowser
|
beaker
|
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-p…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-12079
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210484
|
8.8 |
HIGH
Network
|
mappresspro
|
mappress
|
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12077
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210485
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
|
CWE-352
Origin Validation Error
|
CVE-2020-12076
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210486
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12075
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210487
|
8.8 |
HIGH
Network
|
webtoffee
|
import_export_wordpress_users
|
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
|
CWE-269
Improper Privilege Management
|
CVE-2020-12074
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210488
|
8.8 |
HIGH
Network
|
cyberchimps
|
gutenberg_\&_elementor_templates_importer_for_responsive
|
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
|
NVD-CWE-Other
|
CVE-2020-12073
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210489
|
4.8 |
MEDIUM
Network
|
anchorcms
|
anchor
|
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12071
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210490
|
7.5 |
HIGH
Network
|
teeworlds opensuse fedoraproject debian canonical
|
teeworlds leap backports_sle fedora debian_linux ubuntu_linux
|
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
|
CWE-20
Improper Input Validation
|
CVE-2020-12066
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|