|
210531
|
7.5 |
HIGH
Network
|
acf_to_rest_api_project
|
acf_to_rest_api
|
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/optio…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-13700
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210532
|
9.8 |
CRITICAL
Network
|
bitrix24
|
bitrix24
|
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta n…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13484
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210533
|
6.1 |
MEDIUM
Network
|
bitrix24
|
bitrix24
|
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13483
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210534
|
8.8 |
HIGH
Network
|
expressionengine
|
expressionengine
|
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (me…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13443
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210535
|
5.4 |
MEDIUM
Network
|
verint
|
workforce_optimization
|
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13480
|
2024-11-21 14:01 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210536
|
6.1 |
MEDIUM
Network
|
victorcms_project
|
victorcms
|
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13427
|
2024-11-21 14:01 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210537
|
6.5 |
MEDIUM
Network
|
bdtask
|
multi-scheduler
|
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
|
CWE-352
Origin Validation Error
|
CVE-2020-13426
|
2024-11-21 14:01 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210538
|
9.8 |
CRITICAL
Network
|
gvectors
|
wpdiscuz
|
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments reques…
|
CWE-89
SQL Injection
|
CVE-2020-13640
|
2024-11-21 14:01 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210539
|
7.5 |
HIGH
Network
|
heinekingmedia
|
stashcat
|
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end en…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-13637
|
2024-11-21 14:01 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210540
|
7.8 |
HIGH
Local
|
geti2p
|
i2p
|
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-13431
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|