|
210361
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP …
|
CWE-352
Origin Validation Error
|
CVE-2020-13569
|
2024-11-21 14:01 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210362
|
7.5 |
HIGH
Network
|
silabs
|
micrium_uc-http
|
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP requ…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13582
|
2024-11-21 14:01 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210363
|
7.5 |
HIGH
Network
|
freyrscada
|
iec-60879-5-104_server_simulator
|
A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An at…
|
CWE-697
Incorrect Comparison
|
CVE-2020-13559
|
2024-11-21 14:01 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210364
|
9.8 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13452
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210365
|
9.8 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
|
CWE-459
Incomplete Cleanup
|
CVE-2020-13451
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210366
|
9.8 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS,…
|
CWE-22
Path Traversal
|
CVE-2020-13450
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210367
|
7.5 |
HIGH
Network
|
thecodingmachine
|
gotenberg
|
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
|
CWE-22
Path Traversal
|
CVE-2020-13449
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210368
|
7.5 |
HIGH
Network
|
rockwellautomation
|
rslinx
|
A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-13573
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210369
|
7.8 |
HIGH
Local
|
softmaker
|
softmaker_office
|
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the docu…
|
CWE-787 CWE-681
Out-of-bounds Write Incorrect Conversion between Numeric Types
|
CVE-2020-13545
|
2024-11-21 14:01 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210370
|
7.8 |
HIGH
Local
|
softmaker
|
softmaker_office
|
An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the documen…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2020-13544
|
2024-11-21 14:01 |
2021-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|