|
210041
|
6.1 |
MEDIUM
Network
|
djangoproject fedoraproject canonical netapp debian oracle
|
django fedora ubuntu_linux steelstore_cloud_integrated_storage sra_plugin debian_linux zfs_storage_appliance_kit
|
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13596
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210042
|
6.7 |
MEDIUM
Local
|
systemd_project netapp fedoraproject
|
systemd solidfire_\&_hci_management_node active_iq_unified_manager fedora
|
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user acc…
|
CWE-269
Improper Privilege Management
|
CVE-2020-13776
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210043
|
6.5 |
MEDIUM
Network
|
znc fedoraproject
|
znc fedora
|
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13775
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210044
|
7.5 |
HIGH
Network
|
rocketgenius
|
gravityforms
|
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
|
CWE-200
Information Exposure
|
CVE-2020-13764
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210045
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-13763
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210046
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13762
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210047
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13761
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210048
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-13760
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210049
|
7.5 |
HIGH
Network
|
vm-memory_project
|
vm-memory
|
rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP networking) because read_obj and write_obj do not properly access memory. This affects…
|
CWE-362 CWE-662
Race Condition Improper Synchronization
|
CVE-2020-13759
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210050
|
6.7 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-13754
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|