|
209971
|
7.5 |
HIGH
Network
|
health
|
covidsafe
|
Caching of GATT characteristic values (TempID) in COVIDSafe v1.0.15 and v1.0.16 allows a remote attacker to long-term re-identify an Android device running COVIDSafe.
|
CWE-459
Incomplete Cleanup
|
CVE-2020-12857
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209972
|
9.8 |
CRITICAL
Network
|
alberta tracetogether health
|
abtracetogether tracetogether covidsafe
|
OpenTrace, as used in COVIDSafe through v1.0.17, TraceTogether, ABTraceTogether, and other applications on iOS and Android, allows remote attackers to conduct long-term re-identification attacks and …
|
NVD-CWE-noinfo
|
CVE-2020-12856
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209973
|
7.5 |
HIGH
Network
|
gwtupload_project
|
gwtupload
|
An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13128
|
2024-11-21 14:00 |
2020-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209974
|
9.9 |
CRITICAL
Network
|
elementor
|
elementor_page_builder
|
An issue was discovered in the Elementor Pro plugin before 2.9.4 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13125. An attacker with the Subscriber role can uploa…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-13126
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209975
|
6.5 |
MEDIUM
Network
|
brainstormforce
|
ultimate_addons_for_elementor
|
An issue was discovered in the "Ultimate Addons for Elementor" plugin before 1.24.2 for WordPress, as exploited in the wild in May 2020 in conjunction with CVE-2020-13126. Unauthenticated attackers c…
|
NVD-CWE-noinfo
|
CVE-2020-13125
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209976
|
6.1 |
MEDIUM
Network
|
rcos
|
submitty
|
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
|
CWE-601
Open Redirect
|
CVE-2020-13121
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209977
|
9.8 |
CRITICAL
Network
|
mikrotik-router-monitoring-system_project
|
mikrotik-router-monitoring-system
|
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community.php via the parameter community.
|
CWE-89
SQL Injection
|
CVE-2020-13118
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209978
|
7.5 |
HIGH
Network
|
naviserver_project
|
naviserver
|
NaviServer 4.99.4 to 4.99.19 allows denial of service due to the nsd/driver.c ChunkedDecode function not properly validating the length of a chunk. A remote attacker can craft a chunked-transfer requ…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2020-13111
|
2024-11-21 14:00 |
2020-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209979
|
7.8 |
HIGH
Local
|
kerberos_project
|
kerberos
|
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because o…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2020-13110
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209980
|
9.8 |
CRITICAL
Network
|
seta
|
morita_shogi_64
|
Morita Shogi 64 through 2020-05-02 for Nintendo 64 devices allows remote attackers to execute arbitrary code via crafted packet data to the built-in modem because 0x800b3e94 (aka the IF subcommand to…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-13109
|
2024-11-21 14:00 |
2020-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|