|
213811
|
6.1 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/websites/website.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13797
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213812
|
6.1 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS through 2.8.7. It allows XSS because of a lack of purify calls in lib/packages/structure/structure.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13796
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213813
|
5.3 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
|
CWE-22
Path Traversal
|
CVE-2020-13795
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213814
|
4.3 |
MEDIUM
Network
|
playtube
|
playtube
|
PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.
|
CWE-22
Path Traversal
|
CVE-2020-13792
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213815
|
8.1 |
HIGH
Network
|
libjpeg-turbo mozilla
|
libjpeg-turbo mozjpeg
|
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-13790
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213816
|
8.2 |
HIGH
Network
|
grafana fedoraproject netapp opensuse
|
grafana fedora e-series_performance_analyzer leap backports_sle
|
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL a…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13379
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213817
|
7.5 |
HIGH
Network
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L Ax 1.20B01 Beta devices have Cleartext Transmission of Sensitive Information.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-13787
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213818
|
8.8 |
HIGH
Network
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2020-13786
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213819
|
7.5 |
HIGH
Network
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L Ax 1.20B01 Beta devices have Inadequate Encryption Strength.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2020-13785
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213820
|
7.5 |
HIGH
Network
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L Ax 1.20B01 Beta devices have a predictable seed in a Pseudo-Random Number Generator.
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2020-13784
|
2024-11-21 14:01 |
2020-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|