|
210941
|
6.5 |
MEDIUM
Network
|
zohocorp
|
manageengine_servicedesk_plus
|
Zoho ManageEngine Service Plus before 11.1 build 11112 allows low-privilege authenticated users to discover the File Protection password via a getFileProtectionSettings call to AjaxServlet.
|
CWE-862
Missing Authorization
|
CVE-2020-13154
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210942
|
6.1 |
MEDIUM
Network
|
misp
|
misp
|
app/View/Events/resolved_attributes.ctp in MISP before 2.4.126 has XSS in the resolved attributes view.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13153
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210943
|
5.4 |
MEDIUM
Network
|
dolibarr
|
dolibarr
|
Dolibarr before 11.0.4 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13094
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210944
|
7.8 |
HIGH
Local
|
msi
|
dragon_center
|
Weak permissions on the "%PROGRAMDATA%\MSI\Dragon Center" folder in Dragon Center before 2.6.2003.2401, shipped with Micro-Star MSI Gaming laptops, allows local authenticated users to overwrite syste…
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13149
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210945
|
8.8 |
HIGH
Network
|
edx
|
open_edx_platform
|
Studio in Open edX Ironwood 2.5 allows CSV injection because an added cohort in Course>Instructor>Cohorts may contain a formula that is exported via the "Course>Data Downloads>Reports>Download profil…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2020-13146
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210946
|
5.4 |
MEDIUM
Network
|
edx
|
open_edx_platform
|
Studio in Open edX Ironwood 2.5 allows users to upload SVG files via the "Content>File Uploads" screen. These files can contain JavaScript code and thus lead to Stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13145
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210947
|
8.8 |
HIGH
Network
|
edx
|
open_edx_platform
|
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>New subsection>New unit>Add new component>Problem button>Advanced tab>Custom Pyth…
|
CWE-94 CWE-862
Code Injection Missing Authorization
|
CVE-2020-13144
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210948
|
6.5 |
MEDIUM
Network
|
linux opensuse debian canonical netapp
|
linux_kernel leap debian_linux ubuntu_linux cloud_backup element_software steelstore_cloud_integrated_storage solidfire hci_management_node active_iq_unified_manager sol…
|
gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attack…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13143
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210949
|
7.5 |
HIGH
Network
|
dlink
|
dsp-w215_firmware
|
D-Link DSP-W215 1.26b03 devices send an obfuscated hash that can be retrieved and understood by a network sniffer.
|
NVD-CWE-noinfo
|
CVE-2020-13136
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210950
|
6.5 |
MEDIUM
Adjacent
|
dlink
|
dsp-w215_firmware
|
D-Link DSP-W215 1.26b03 devices allow information disclosure by intercepting messages on the local network, as demonstrated by a Squid Proxy.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2020-13135
|
2024-11-21 14:00 |
2020-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|