|
211751
|
9.8 |
CRITICAL
Network
|
gvectors
|
wpdiscuz
|
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments reques…
|
CWE-89
SQL Injection
|
CVE-2020-13640
|
2024-11-21 14:01 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211752
|
7.5 |
HIGH
Network
|
heinekingmedia
|
stashcat
|
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end en…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-13637
|
2024-11-21 14:01 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211753
|
7.8 |
HIGH
Local
|
geti2p
|
i2p
|
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-13431
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211754
|
6.1 |
MEDIUM
Network
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the log…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13652
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211755
|
7.8 |
HIGH
Local
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by …
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-13651
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211756
|
7.5 |
HIGH
Network
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a prox…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13650
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211757
|
9.8 |
CRITICAL
Network
|
morganstanley
|
hobbes
|
In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remo…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-13656
|
2024-11-21 14:01 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211758
|
10.0 |
CRITICAL
Network
|
the_rolling_proximity_identifier_project
|
the_rolling_proximity_identifier
|
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary tempor…
|
CWE-200
Information Exposure
|
CVE-2020-13702
|
2024-11-21 14:01 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211759
|
8.8 |
HIGH
Network
|
liferay
|
liferay_portal
|
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which al…
|
CWE-74 CWE-862
Injection Missing Authorization
|
CVE-2020-13445
|
2024-11-21 14:01 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211760
|
6.5 |
MEDIUM
Network
|
liferay
|
liferay_portal
|
Liferay Portal 7.x before 7.3.2, and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 5 does not sanitize the information returned by the DDMDataProvider API, which…
|
NVD-CWE-noinfo
|
CVE-2020-13444
|
2024-11-21 14:01 |
2020-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|