|
213481
|
9.8 |
CRITICAL
Network
|
facade
|
ignition
|
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021…
|
NVD-CWE-noinfo
|
CVE-2020-13909
|
2024-11-21 14:02 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213482
|
5.5 |
MEDIUM
Local
|
ffmpeg canonical debian
|
ffmpeg ubuntu_linux debian_linux
|
FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_inp…
|
CWE-416
Use After Free
|
CVE-2020-13904
|
2024-11-21 14:02 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213483
|
7.1 |
HIGH
Local
|
imagemagick
|
imagemagick
|
ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13902
|
2024-11-21 14:02 |
2020-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213484
|
6.1 |
MEDIUM
Network
|
hesk
|
hesk
|
HESK before 3.1.10 allows reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13897
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213485
|
8.8 |
HIGH
Network
|
p5-crypt-perl_project
|
p5-crypt-perl
|
Crypt::Perl::ECDSA in the Crypt::Perl (aka p5-Crypt-Perl) module before 0.32 for Perl fails to verify correct ECDSA signatures when r and s are small and when s = 1. This happens when using the curve…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2020-13895
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213486
|
7.5 |
HIGH
Network
|
dext5
|
dext5
|
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-13894
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213487
|
5.4 |
MEDIUM
Network
|
laborator
|
neon
|
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13890
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213488
|
5.4 |
MEDIUM
Network
|
bludit
|
bludit
|
showAlert() in the administration panel in Bludit 3.12.0 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13889
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213489
|
6.7 |
MEDIUM
Network
|
wso2
|
identity_server_as_key_manager api_microgateway api_manager
|
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
|
CWE-611
XXE
|
CVE-2020-13883
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213490
|
7.5 |
HIGH
Network
|
pam_tacplus_project debian canonical arista
|
pam_tacplus debian_linux ubuntu_linux cloudvision_portal
|
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-13881
|
2024-11-21 14:02 |
2020-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|