|
210901
|
10.0 |
CRITICAL
Network
|
beakerbrowser
|
beaker
|
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-p…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2020-12079
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210902
|
8.8 |
HIGH
Network
|
mappresspro
|
mappress
|
The mappress-google-maps-for-wordpress plugin before 2.53.9 for WordPress does not correctly implement AJAX functions with nonces (or capability checks), leading to remote code execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12077
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210903
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks CSRF nonce checks for AJAX actions. One consequence of this is stored XSS.
|
CWE-352
Origin Validation Error
|
CVE-2020-12076
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210904
|
8.8 |
HIGH
Network
|
supsystic
|
data_tables_generator
|
The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-12075
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210905
|
8.8 |
HIGH
Network
|
webtoffee
|
import_export_wordpress_users
|
The users-customers-import-export-for-wp-woocommerce plugin before 1.3.9 for WordPress allows subscribers to import administrative accounts via CSV.
|
CWE-269
Improper Privilege Management
|
CVE-2020-12074
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210906
|
8.8 |
HIGH
Network
|
cyberchimps
|
gutenberg_\&_elementor_templates_importer_for_responsive
|
The responsive-add-ons plugin before 2.2.7 for WordPress has incorrect access control for wp-admin/admin-ajax.php?action= requests.
|
NVD-CWE-Other
|
CVE-2020-12073
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210907
|
4.8 |
MEDIUM
Network
|
anchorcms
|
anchor
|
Anchor 0.12.7 allows admins to cause XSS via crafted post content.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12071
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210908
|
7.5 |
HIGH
Network
|
teeworlds opensuse fedoraproject debian canonical
|
teeworlds leap backports_sle fedora debian_linux ubuntu_linux
|
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
|
CWE-20
Improper Input Validation
|
CVE-2020-12066
|
2024-11-21 13:59 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210909
|
7.5 |
HIGH
Network
|
linuxfoundation canonical
|
ceph ubuntu_linux
|
An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12059
|
2024-11-21 13:59 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210910
|
7.5 |
HIGH
Network
|
mediawiki
|
mediawiki
|
The CentralAuth extension through REL1_34 for MediaWiki allows remote attackers to obtain sensitive hidden account information via an api.php?action=query&meta=globaluserinfo&guiuser= request. In oth…
|
NVD-CWE-noinfo
|
CVE-2020-12051
|
2024-11-21 13:59 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|