|
209511
|
5.4 |
MEDIUM
Network
|
elementor
|
elementor_page_builder
|
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from multiple stored XSS vulnerabilities. An author user can create posts that result in stored XSS vulnerabilities, by using a cr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13865
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209512
|
5.4 |
MEDIUM
Network
|
elementor
|
elementor_page_builder
|
The Elementor Page Builder plugin before 2.9.9 for WordPress suffers from a stored XSS vulnerability. An author user can create posts that result in a stored XSS by using a crafted payload in custom …
|
CWE-79
Cross-site Scripting
|
CVE-2020-13864
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209513
|
5.4 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13870
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209514
|
5.4 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.6 for Craft CMS. There is stored XSS via a guest name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13869
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209515
|
6.5 |
MEDIUM
Network
|
verbb
|
comments
|
An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. CSRF affects comment integrity.
|
CWE-352
Origin Validation Error
|
CVE-2020-13868
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209516
|
5.5 |
MEDIUM
Local
|
targetcli-fb_project fedoraproject
|
targetcli-fb fedora
|
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13867
|
2024-11-21 14:02 |
2020-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209517
|
7.5 |
HIGH
Network
|
mqtt
|
mqtt
|
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the abili…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13849
|
2024-11-21 14:02 |
2020-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209518
|
8.1 |
HIGH
Network
|
loadbalancer
|
enterprise_va_max
|
The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and…
|
CWE-22
Path Traversal
|
CVE-2020-13377
|
2024-11-21 14:01 |
2023-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209519
|
8.8 |
HIGH
Network
|
loadbalancer
|
enterprise_va_max
|
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
|
CWE-78
OS Command
|
CVE-2020-13378
|
2024-11-21 14:01 |
2023-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209520
|
7.2 |
HIGH
Network
|
rukovoditel
|
rukovoditel
|
Multiple exploitable SQL injection vulnerabilities exist in the 'entities/fields' page of the Rukovoditel Project Management App 2.7.2. A specially crafted HTTP request can lead to SQL injection. An …
|
CWE-89
SQL Injection
|
CVE-2020-13590
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|