|
209521
|
9.8 |
CRITICAL
Network
|
open-emr phpgacl_project
|
openemr phpgacl
|
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.
|
CWE-89
SQL Injection
|
CVE-2020-13567
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209522
|
5.5 |
MEDIUM
Local
|
pixar
|
openusd
|
An exploitable vulnerability exists in the way Pixar OpenUSD 20.05 handles file offsets in binary USD files. A specially crafted malformed file can trigger an arbitrary out-of-bounds memory access th…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13495
|
2024-11-21 14:01 |
2022-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209523
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API modul…
|
NVD-CWE-Other
|
CVE-2020-13677
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209524
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
The QuickEdit module does not properly check access to fields in some circumstances, which can lead to unintended disclosure of field data. Sites are only affected if the QuickEdit module (which come…
|
CWE-863
Incorrect Authorization
|
CVE-2020-13676
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209525
|
9.8 |
CRITICAL
Network
|
drupal
|
drupal
|
Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, which causes an access bypass vulnerability. An attacker migh…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13675
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209526
|
6.5 |
MEDIUM
Network
|
drupal
|
drupal
|
The QuickEdit module does not properly validate access to routes, which could allow cross-site request forgery under some circumstances and lead to possible data integrity issues. Sites are only affe…
|
CWE-352
Origin Validation Error
|
CVE-2020-13674
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209527
|
6.1 |
MEDIUM
Network
|
drupal
|
entity_embed
|
The Entity Embed module provides a filter to allow embedding entities in content fields. In certain circumstances, the filter could allow an unprivileged user to inject HTML into a page when it is ac…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13673
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209528
|
6.1 |
MEDIUM
Network
|
drupal
|
drupal
|
Cross-site Scripting (XSS) vulnerability in Drupal core's sanitization API fails to properly filter cross-site scripting under certain circumstances. This issue affects: Drupal Core 9.1.x versions pr…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13672
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209529
|
7.5 |
HIGH
Network
|
drupal
|
drupal
|
Information Disclosure vulnerability in file module of Drupal Core allows an attacker to gain access to the file metadata of a permanent private file that they do not have access to by guessing the I…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2020-13670
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209530
|
6.1 |
MEDIUM
Network
|
drupal
|
drupal
|
Cross-site Scripting (XSS) vulnerability in ckeditor of Drupal Core allows attacker to inject XSS. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10.; 8.9.x versions prior to 8.9.6; 9.0.…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13669
|
2024-11-21 14:01 |
2022-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|