|
210281
|
7.5 |
HIGH
Network
|
mqtt
|
mqtt
|
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the abili…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13849
|
2024-11-21 14:02 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210282
|
8.1 |
HIGH
Network
|
loadbalancer
|
enterprise_va_max
|
The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and…
|
CWE-22
Path Traversal
|
CVE-2020-13377
|
2024-11-21 14:01 |
2023-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210283
|
8.8 |
HIGH
Network
|
loadbalancer
|
enterprise_va_max
|
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2020-13378
|
2024-11-21 14:01 |
2023-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210284
|
7.2 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An …
|
CWE-89
SQL Injection
|
CVE-2020-13590
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210285
|
9.8 |
CRITICAL
Network
|
open-emr phpgacl_project
|
openemr phpgacl
|
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
|
CWE-89
SQL Injection
|
CVE-2020-13567
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210286
|
5.5 |
MEDIUM
Local
|
pixar
|
openusd
|
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access th…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13495
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210287
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API modul…
|
NVD-CWE-Other
|
CVE-2020-13677
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210288
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which come…
|
CWE-863
Incorrect Authorization
|
CVE-2020-13676
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210289
|
9.8 |
CRITICAL
Network
|
drupal
|
drupal
|
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker migh…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13675
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210290
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affe…
|
CWE-352
Origin Validation Error
|
CVE-2020-13674
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|