|
210611
|
7.5 |
HIGH
Network
|
rocketgenius
|
gravityforms
|
common.php in the Gravity Forms plugin before 2.4.9 for WordPress can leak hashed passwords because user_pass is not considered a special case for a $current_user->get($property) call.
|
CWE-200
Information Exposure
|
CVE-2020-13764
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210612
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-13763
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210613
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, incorrect input validation of the module tag option in com_modules allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13762
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210614
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13761
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210615
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-13760
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210616
|
7.5 |
HIGH
Network
|
vm-memory_project
|
vm-memory
|
rust-vmm vm-memory before 0.1.1 and 0.2.x before 0.2.1 allows attackers to cause a denial of service (loss of IP networking) because read_obj and write_obj do not properly access memory. This affects…
|
CWE-362 CWE-662
Race Condition Improper Synchronization
|
CVE-2020-13759
|
2024-11-21 14:01 |
2020-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210617
|
6.7 |
MEDIUM
Local
|
qemu canonical debian
|
qemu ubuntu_linux debian_linux
|
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2020-13754
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210618
|
6.0 |
MEDIUM
Network
|
docker fedoraproject debian broadcom
|
engine fedora debian_linux sannav
|
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts…
|
CWE-20
Improper Input Validation
|
CVE-2020-13401
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210619
|
2.5 |
LOW
Local
|
qemu debian opensuse canonical
|
qemu debian_linux leap ubuntu_linux
|
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13659
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210620
|
6.1 |
MEDIUM
Network
|
bitrix
|
bitrix24
|
modules/security/classes/general.post_filter.php/post_filter.php in the Web Application Firewall in Bitrix24 through 20.0.950 allows XSS by placing %00 before the payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13758
|
2024-11-21 14:01 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|