|
212541
|
5.5 |
MEDIUM
Local
|
sqlite fedoraproject
|
sqlite fedora
|
SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13435
|
2024-11-21 14:01 |
2020-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212542
|
5.5 |
MEDIUM
Local
|
sqlite debian fedoraproject canonical freebsd oracle apple
|
sqlite debian_linux fedora ubuntu_linux freebsd outside_in_technology communications_network_charging_and_control communications_cloud_native_core_policy iphone_os watchos<…
|
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-13434
|
2024-11-21 14:01 |
2020-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212543
|
9.8 |
CRITICAL
Network
|
adminpanel_project
|
adminpanel
|
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
|
CWE-89
SQL Injection
|
CVE-2020-13433
|
2024-11-21 14:01 |
2020-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212544
|
6.1 |
MEDIUM
Network
|
grafana
|
grafana
|
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13430
|
2024-11-21 14:01 |
2020-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212545
|
5.4 |
MEDIUM
Network
|
grafana
|
piechart-panel
|
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13429
|
2024-11-21 14:01 |
2020-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212546
|
7.1 |
HIGH
Adjacent
|
thetrackr
|
trackr_firmware
|
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
|
CWE-862
Missing Authorization
|
CVE-2020-13425
|
2024-11-21 14:01 |
2020-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212547
|
6.5 |
MEDIUM
Network
|
xcloner
|
xcloner
|
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
|
NVD-CWE-noinfo
|
CVE-2020-13424
|
2024-11-21 14:01 |
2020-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212548
|
9.8 |
CRITICAL
Network
|
aviatrix
|
controller gateway vpn_client
|
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain O…
|
NVD-CWE-noinfo
|
CVE-2020-13417
|
2024-11-21 14:01 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212549
|
6.5 |
MEDIUM
Network
|
aviatrix
|
controller
|
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Reque…
|
CWE-352
Origin Validation Error
|
CVE-2020-13416
|
2024-11-21 14:01 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212550
|
7.5 |
HIGH
Network
|
aviatrix
|
controller
|
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired o…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-13415
|
2024-11-21 14:01 |
2020-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|