|
210391
|
7.5 |
HIGH
Network
|
gwtupload_project
|
gwtupload
|
An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13128
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210392
|
9.9 |
CRITICAL
Network
|
elementor
|
elementor_page_builder
|
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can uploa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13126
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210393
|
6.5 |
MEDIUM
Network
|
brainstormforce
|
ultimate_addons_for_elementor
|
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers c…
|
NVD-CWE-noinfo
|
CVE-2020-13125
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210394
|
6.1 |
MEDIUM
Network
|
rcos
|
submitty
|
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
|
CWE-601
Open Redirect
|
CVE-2020-13121
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210395
|
9.8 |
CRITICAL
Network
|
mikrotik-router-monitoring-system_project
|
mikrotik-router-monitoring-system
|
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
|
CWE-89
SQL Injection
|
CVE-2020-13118
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210396
|
7.5 |
HIGH
Network
|
naviserver_project
|
naviserver
|
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer requ…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-13111
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210397
|
7.8 |
HIGH
Local
|
kerberos_project
|
kerberos
|
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because o…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-13110
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210398
|
9.8 |
CRITICAL
Network
|
seta
|
morita_shogi_64
|
Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13109
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210399
|
5.3 |
MEDIUM
Network
|
ispyconnect
|
agent_dvr
|
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
|
CWE-22
Path Traversal
|
CVE-2020-13093
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210400
|
9.8 |
CRITICAL
Network
|
scikit-learn
|
scikit-learn
|
scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call. NOTE: third …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2020-13092
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|