|
209531
|
8.8 |
HIGH
Network
|
teamviewer
|
teamviewer
|
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10:…
|
CWE-88
Argument Injection
|
CVE-2020-13699
|
2024-11-21 14:01 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209532
|
7.5 |
HIGH
Network
|
microweber
|
microweber
|
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13405
|
2024-11-21 14:01 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209533
|
4.3 |
MEDIUM
Network
|
linuxfoundation
|
harbor
|
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13788
|
2024-11-21 14:01 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209534
|
7.5 |
HIGH
Network
|
sylabs
|
singularity
|
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF fil…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-13847
|
2024-11-21 14:01 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209535
|
7.5 |
HIGH
Network
|
sylabs
|
singularity
|
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
|
NVD-CWE-Other
|
CVE-2020-13846
|
2024-11-21 14:01 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209536
|
7.5 |
HIGH
Network
|
sylabs
|
singularity
|
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compare…
|
CWE-347 CWE-354
Improper Verification of Cryptographic Signature Improper Validation of Integrity Check Value
|
CVE-2020-13845
|
2024-11-21 14:01 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209537
|
10.0 |
CRITICAL
Network
|
wpewebkit webkitgtk fedoraproject debian canonical opensuse
|
wpe_webkit webkitgtk fedora debian_linux ubuntu_linux leap
|
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg-des…
|
CWE-20
Improper Input Validation
|
CVE-2020-13753
|
2024-11-21 14:01 |
2020-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209538
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An XSS vulnerability exists in the Webmail component of Zimbra Collaboration Suite before 8.8.15 Patch 11. It allows an attacker to inject executable JavaScript into the account name of a user's prof…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13653
|
2024-11-21 14:01 |
2020-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209539
|
9.8 |
CRITICAL
Network
|
locutus
|
locutus_php
|
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
|
CWE-78
OS Command
|
CVE-2020-13619
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209540
|
7.5 |
HIGH
Network
|
os4ed
|
opensis
|
openSIS through 7.4 allows Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2020-13383
|
2024-11-21 14:01 |
2020-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|