|
210271
|
5.4 |
MEDIUM
Network
|
bludit
|
bludit
|
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13889
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210272
|
6.7 |
MEDIUM
Network
|
wso2
|
identity_server_as_key_manager api_microgateway api_manager
|
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
|
CWE-611
XXE
|
CVE-2020-13883
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210273
|
7.5 |
HIGH
Network
|
pam_tacplus_project debian canonical arista
|
pam_tacplus debian_linux ubuntu_linux cloudvision_portal
|
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-13881
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210274
|
7.5 |
HIGH
Network
|
sqlite fedoraproject debian oracle siemens netapp
|
sqlite fedora debian_linux hyperion_infrastructure_technology enterprise_manager_ops_center communications_network_charging_and_control zfs_storage_appliance_kit communications_m…
|
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
|
CWE-416
Use After Free
|
CVE-2020-13871
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210275
|
5.4 |
MEDIUM
Network
|
elementor
|
elementor_page_builder
|
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13865
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210276
|
5.4 |
MEDIUM
Network
|
elementor
|
elementor_page_builder
|
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13864
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210277
|
5.4 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13870
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210278
|
5.4 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13869
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210279
|
6.5 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
|
CWE-352
Origin Validation Error
|
CVE-2020-13868
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210280
|
5.5 |
MEDIUM
Local
|
targetcli-fb_project fedoraproject
|
targetcli-fb fedora
|
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13867
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|