Search Results (323565 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-13476 1 Nchsoftware 1 Express Invoice 2024-11-21 4.8 Medium
NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
CVE-2020-13474 1 Nchsoftware 1 Express Accounts 2024-11-21 6.5 Medium
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
CVE-2020-13473 1 Nchsoftware 1 Express Accounts 2024-11-21 5.5 Medium
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
CVE-2020-13472 1 Gigadevice 2 Gd32f103, Gd32f103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.
CVE-2020-13471 1 Apexmic 2 Apm32f103, Apm32f103 Firmware 2024-11-21 6.8 Medium
Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVE-2020-13470 1 Gigadevice 4 Gd32f103, Gd32f103 Firmware, Gd32f130 and 1 more 2024-11-21 4.6 Medium
Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data.
CVE-2020-13469 1 Gigadevice 2 Gd32vf103, Gd32vf103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU.
CVE-2020-13468 1 Gigadevice 2 Gd32f130, Gd32f130 Firmware 2024-11-21 6.8 Medium
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
CVE-2020-13467 1 Cksic 2 Cks32f103, Cks32f103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
CVE-2020-13466 1 St 2 Stm32f103, Stm32f103 Firmware 2024-11-21 6.8 Medium
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVE-2020-13465 1 Gigadevice 2 Gd32f103, Gd32f103 Firmware 2024-11-21 6.8 Medium
The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.
CVE-2020-13464 1 Cksic 2 Cks32f103, Cks32f103 Firmware 2024-11-21 4.2 Medium
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.
CVE-2020-13463 1 Apexmic 2 Apm32f103, Apm32f103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
CVE-2020-13462 1 Tufin 1 Securetrack 2024-11-21 5.7 Medium
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.
CVE-2020-13461 1 Tufin 1 Securetrack 2024-11-21 4.3 Medium
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".
CVE-2020-13460 1 Tufin 1 Securetrack 2024-11-21 8.8 High
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.
CVE-2020-13459 1 Verbb 1 Image Resizer 2024-11-21 5.4 Medium
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.
CVE-2020-13458 1 Verbb 1 Image Resizer 2024-11-21 8.8 High
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.
CVE-2020-13452 1 Thecodingmachine 1 Gotenberg 2024-11-21 9.8 Critical
In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.
CVE-2020-13451 1 Thecodingmachine 1 Gotenberg 2024-11-21 9.8 Critical
An incomplete-cleanup vulnerability in the Office rendering engine of Gotenberg through 6.2.1 allows an attacker to overwrite LibreOffice configuration files and execute arbitrary code via macros.