|
211491
|
5.4 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13869
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211492
|
6.5 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
|
CWE-352
Origin Validation Error
|
CVE-2020-13868
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211493
|
5.5 |
MEDIUM
Local
|
targetcli-fb_project fedoraproject
|
targetcli-fb fedora
|
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13867
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211494
|
7.5 |
HIGH
Network
|
mqtt
|
mqtt
|
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the abili…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13849
|
2024-11-21 14:02 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211495
|
8.1 |
HIGH
Network
|
loadbalancer
|
enterprise_va_max
|
The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and…
|
CWE-22
Path Traversal
|
CVE-2020-13377
|
2024-11-21 14:01 |
2023-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211496
|
8.8 |
HIGH
Network
|
loadbalancer
|
enterprise_va_max
|
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2020-13378
|
2024-11-21 14:01 |
2023-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211497
|
7.2 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An …
|
CWE-89
SQL Injection
|
CVE-2020-13590
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211498
|
9.8 |
CRITICAL
Network
|
open-emr phpgacl_project
|
openemr phpgacl
|
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
|
CWE-89
SQL Injection
|
CVE-2020-13567
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211499
|
5.5 |
MEDIUM
Local
|
pixar
|
openusd
|
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access th…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13495
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211500
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API modul…
|
NVD-CWE-Other
|
CVE-2020-13677
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|