|
209541
|
9.1 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS through 7.4 has Incorrect Access Control.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13382
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209542
|
9.8 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS through 7.4 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-13381
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209543
|
9.8 |
CRITICAL
Network
|
os4ed
|
opensis
|
openSIS before 7.4 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2020-13380
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209544
|
5.5 |
MEDIUM
Local
|
avast
|
avg_antivirus free_antivirus
|
An elevation of privilege vulnerability exists in Avast Free Antivirus and AVG AntiVirus Free before 20.4 due to improperly handling hard links. The vulnerability allows local users to take control o…
|
NVD-CWE-noinfo
|
CVE-2020-13657
|
2024-11-21 14:01 |
2020-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209545
|
4.8 |
MEDIUM
Network
|
form_builder_for_magento_2_project
|
form_builder_for_magento_2
|
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13423
|
2024-11-21 14:01 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209546
|
7.5 |
HIGH
Network
|
acf_to_rest_api_project
|
acf_to_rest_api
|
An issue was discovered in the acf-to-rest-api plugin through 3.1.0 for WordPress. It allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/optio…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2020-13700
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209547
|
9.8 |
CRITICAL
Network
|
bitrix24
|
bitrix24
|
Bitrix24 through 20.0.975 allows SSRF via an intranet IP address in the services/main/ajax.php?action=attachUrlPreview url parameter, if the destination URL hosts an HTML document containing '<meta n…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13484
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209548
|
6.1 |
MEDIUM
Network
|
bitrix24
|
bitrix24
|
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13483
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209549
|
8.8 |
HIGH
Network
|
expressionengine
|
expressionengine
|
ExpressionEngine before 5.3.2 allows remote attackers to upload and execute arbitrary code in a .php%20 file via Compose Msg, Add attachment, and Save As Draft actions. A user with low privileges (me…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13443
|
2024-11-21 14:01 |
2020-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209550
|
5.4 |
MEDIUM
Network
|
verint
|
workforce_optimization
|
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13480
|
2024-11-21 14:01 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|