|
210511
|
8.8 |
HIGH
Network
|
quadra-informatique
|
atos\/sips
|
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
|
CWE-78
OS Command
|
CVE-2020-13404
|
2024-11-21 14:01 |
2020-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210512
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme EAC Appliance 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13819
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210513
|
7.1 |
HIGH
Local
|
softperfect
|
ram_disk
|
An exploitable arbitrary file delete vulnerability exists in SoftPerfect RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can allow an unprivileged user to delete any file …
|
NVD-CWE-noinfo
|
CVE-2020-13522
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210514
|
3.3 |
LOW
Local
|
softperfect
|
ram_disk
|
An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive informati…
|
CWE-862
Missing Authorization
|
CVE-2020-13523
|
2024-11-21 14:01 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210515
|
6.1 |
MEDIUM
Network
|
extremenetworks
|
extreme_management_center
|
Extreme Management Center 8.4.1.24 allows unauthenticated reflected XSS via a parameter in a GET request.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13820
|
2024-11-21 14:01 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210516
|
8.8 |
HIGH
Network
|
teamviewer
|
teamviewer
|
TeamViewer Desktop for Windows before 15.8.3 does not properly quote its custom URI handlers. A malicious website could launch TeamViewer with arbitrary parameters, as demonstrated by a teamviewer10:…
|
CWE-88
Argument Injection
|
CVE-2020-13699
|
2024-11-21 14:01 |
2020-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210517
|
7.5 |
HIGH
Network
|
microweber
|
microweber
|
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-13405
|
2024-11-21 14:01 |
2020-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210518
|
4.3 |
MEDIUM
Network
|
linuxfoundation
|
harbor
|
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13788
|
2024-11-21 14:01 |
2020-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210519
|
7.5 |
HIGH
Network
|
sylabs
|
singularity
|
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF fil…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2020-13847
|
2024-11-21 14:01 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210520
|
7.5 |
HIGH
Network
|
sylabs
|
singularity
|
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
|
NVD-CWE-Other
|
CVE-2020-13846
|
2024-11-21 14:01 |
2020-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|