|
212241
|
6.1 |
MEDIUM
Network
|
phpgacl_project open-emr
|
phpgacl openemr
|
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13564
|
2024-11-21 14:01 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212242
|
6.1 |
MEDIUM
Network
|
phpgacl_project open-emr
|
phpgacl openemr
|
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13563
|
2024-11-21 14:01 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212243
|
6.1 |
MEDIUM
Network
|
phpgacl_project open-emr
|
phpgacl openemr
|
A cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbitrary JavaScript execution. An attacker can provide a craf…
|
CWE-79
Cross-site Scripting
|
CVE-2020-13562
|
2024-11-21 14:01 |
2021-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212244
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f91ccd512bcad85832eb6ce). A specially crafted HTTP …
|
CWE-352
Origin Validation Error
|
CVE-2020-13569
|
2024-11-21 14:01 |
2021-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212245
|
7.5 |
HIGH
Network
|
silabs
|
micrium_uc-http
|
A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker can send an HTTP requ…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-13582
|
2024-11-21 14:01 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212246
|
7.5 |
HIGH
Network
|
freyrscada
|
iec-60879-5-104_server_simulator
|
A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An at…
|
CWE-697
Incorrect Comparison
|
CVE-2020-13559
|
2024-11-21 14:01 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212247
|
9.8 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13452
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212248
|
9.8 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.
|
CWE-459
Incomplete Cleanup
|
CVE-2020-13451
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212249
|
9.8 |
CRITICAL
Network
|
thecodingmachine
|
gotenberg
|
A directory traversal vulnerability in file upload function of Gotenberg through 6.2.1 allows an attacker to upload and overwrite any writable files outside the intended folder. This can lead to DoS,…
|
CWE-22
Path Traversal
|
CVE-2020-13450
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212250
|
7.5 |
HIGH
Network
|
thecodingmachine
|
gotenberg
|
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any container files.
|
CWE-22
Path Traversal
|
CVE-2020-13449
|
2024-11-21 14:01 |
2021-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|