|
209551
|
6.1 |
MEDIUM
Network
|
victorcms_project
|
victorcms
|
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13427
|
2024-11-21 14:01 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209552
|
6.5 |
MEDIUM
Network
|
bdtask
|
multi-scheduler
|
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
|
CWE-352
Origin Validation Error
|
CVE-2020-13426
|
2024-11-21 14:01 |
2020-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209553
|
9.8 |
CRITICAL
Network
|
gvectors
|
wpdiscuz
|
A SQL injection issue in the gVectors wpDiscuz plugin 5.3.5 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the order parameter of a wpdLoadMoreComments reques…
|
CWE-89
SQL Injection
|
CVE-2020-13640
|
2024-11-21 14:01 |
2020-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209554
|
7.5 |
HIGH
Network
|
heinekingmedia
|
stashcat
|
An issue was discovered in the stashcat app through 3.9.2 for macOS, Windows, Android, iOS, and possibly other platforms. It stores the client_key, the device_id, and the public key for end-to-end en…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-13637
|
2024-11-21 14:01 |
2020-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209555
|
7.8 |
HIGH
Local
|
geti2p
|
i2p
|
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-13431
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209556
|
6.1 |
MEDIUM
Network
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200528, 2019R2 before p20200430, and 2020R1 before p20200507. A cross-site scripting (XSS) vulnerability exists in the log…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13652
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209557
|
7.8 |
HIGH
Local
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by …
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2020-13651
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209558
|
7.5 |
HIGH
Network
|
digdash
|
digdash
|
An issue was discovered in DigDash 2018R2 before p20200210 and 2019R1 before p20200210. The login page is vulnerable to Server-Side Request Forgery (SSRF) that allows use of the application as a prox…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13650
|
2024-11-21 14:01 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209559
|
9.8 |
CRITICAL
Network
|
morganstanley
|
hobbes
|
In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remo…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2020-13656
|
2024-11-21 14:01 |
2020-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209560
|
10.0 |
CRITICAL
Network
|
the_rolling_proximity_identifier_project
|
the_rolling_proximity_identifier
|
The Rolling Proximity Identifier used in the Apple/Google Exposure Notification API beta through 2020-05-29 enables attackers to circumvent Bluetooth Smart Privacy because there is a secondary tempor…
|
CWE-200
Information Exposure
|
CVE-2020-13702
|
2024-11-21 14:01 |
2020-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|