|
210321
|
8.1 |
HIGH
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
|
CWE-862
Missing Authorization
|
CVE-2020-13422
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210322
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
|
NVD-CWE-Other
|
CVE-2020-13421
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210323
|
9.8 |
CRITICAL
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
|
NVD-CWE-noinfo
|
CVE-2020-13420
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210324
|
5.3 |
MEDIUM
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
|
CWE-22
Path Traversal
|
CVE-2020-13419
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210325
|
6.1 |
MEDIUM
Network
|
openiam
|
openiam
|
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13418
|
2024-11-21 14:01 |
2021-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210326
|
8.8 |
HIGH
Network
|
webkitgtk
|
webkitgtk
|
A code execution vulnerability exists in the AudioSourceProviderGStreamer functionality of Webkit WebKitGTK 2.30.1. A specially crafted web page can lead to a use after free.
|
CWE-416
Use After Free
|
CVE-2020-13558
|
2024-11-21 14:01 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210327
|
7.8 |
HIGH
Local
|
advantech
|
webaccess\/scada
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation …
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13554
|
2024-11-21 14:01 |
2021-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210328
|
6.1 |
MEDIUM
Network
|
nanohttpd
|
nanohttpd
|
An issue was discovered in RouterNanoHTTPD.java in NanoHTTPD through 2.3.1. The GeneralHandler class implements a basic GET handler that prints debug information as an HTML page. Any web server that …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13697
|
2024-11-21 14:01 |
2021-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210329
|
7.8 |
HIGH
Local
|
sytech
|
xlreporter
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory. Depending on the vector chosen, an attacker can overwrite…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13549
|
2024-11-21 14:01 |
2021-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210330
|
8.8 |
HIGH
Local
|
advantech
|
webaccess\/scada
|
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attack…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13555
|
2024-11-21 14:01 |
2021-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|