Export limit exceeded: 369387 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369387 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-13432 | 1 Rejetto | 1 Http File Server | 2024-11-21 | 7.5 High |
| rejetto HFS (aka HTTP File Server) v2.3m Build #300, when virtual files or folders are used, allows remote attackers to trigger an invalid-pointer write access violation via concurrent HTTP requests with a long URI or long HTTP headers. | ||||
| CVE-2020-13431 | 1 Geti2p | 1 I2p | 2024-11-21 | 7.8 High |
| I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory. | ||||
| CVE-2020-13430 | 2 Grafana, Redhat | 3 Grafana, Enterprise Linux, Service Mesh | 2024-11-21 | 6.1 Medium |
| Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource. | ||||
| CVE-2020-13429 | 1 Grafana | 1 Piechart-panel | 2024-11-21 | 5.4 Medium |
| legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option. | ||||
| CVE-2020-13428 | 2 Debian, Videolan | 2 Debian Linux, Vlc Media Player | 2024-11-21 | 7.8 High |
| A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file. | ||||
| CVE-2020-13427 | 1 Victorcms Project | 1 Victorcms | 2024-11-21 | 6.1 Medium |
| Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter. | ||||
| CVE-2020-13426 | 1 Bdtask | 1 Multi-scheduler | 2024-11-21 | 6.5 Medium |
| The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known. | ||||
| CVE-2020-13425 | 1 Thetrackr | 2 Trackr, Trackr Firmware | 2024-11-21 | 7.1 High |
| TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted. | ||||
| CVE-2020-13424 | 1 Xcloner | 1 Xcloner | 2024-11-21 | 6.5 Medium |
| The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure. | ||||
| CVE-2020-13423 | 1 Form Builder For Magento 2 Project | 1 Form Builder For Magento 2 | 2024-11-21 | 4.8 Medium |
| Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header. | ||||
| CVE-2020-13422 | 1 Openiam | 1 Openiam | 2024-11-21 | 8.1 High |
| OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions. | ||||
| CVE-2020-13421 | 1 Openiam | 1 Openiam | 2024-11-21 | 9.8 Critical |
| OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions. | ||||
| CVE-2020-13420 | 1 Openiam | 1 Openiam | 2024-11-21 | 9.8 Critical |
| OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script. | ||||
| CVE-2020-13419 | 1 Openiam | 1 Openiam | 2024-11-21 | 5.3 Medium |
| OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task. | ||||
| CVE-2020-13418 | 1 Openiam | 1 Openiam | 2024-11-21 | 6.1 Medium |
| OpenIAM before 4.2.0.3 allows XSS in the Add New User feature. | ||||
| CVE-2020-13417 | 4 Apple, Aviatrix, Linux and 1 more | 6 Macos, Controller, Gateway and 3 more | 2024-11-21 | 9.8 Critical |
| An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters. | ||||
| CVE-2020-13416 | 1 Aviatrix | 1 Controller | 2024-11-21 | 6.5 Medium |
| An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets. | ||||
| CVE-2020-13415 | 1 Aviatrix | 1 Controller | 2024-11-21 | 7.5 High |
| An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping. | ||||
| CVE-2020-13414 | 1 Aviatrix | 2 Controller, Gateway | 2024-11-21 | 7.5 High |
| An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software. | ||||
| CVE-2020-13413 | 1 Aviatrix | 2 Controller, Vpn Client | 2024-11-21 | 5.3 Medium |
| An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force. | ||||