Search Results (323565 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-13425 1 Thetrackr 2 Trackr, Trackr Firmware 2024-11-21 7.1 High
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
CVE-2020-13424 1 Xcloner 1 Xcloner 2024-11-21 6.5 Medium
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
CVE-2020-13423 1 Form Builder For Magento 2 Project 1 Form Builder For Magento 2 2024-11-21 4.8 Medium
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
CVE-2020-13422 1 Openiam 1 Openiam 2024-11-21 8.1 High
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
CVE-2020-13421 1 Openiam 1 Openiam 2024-11-21 9.8 Critical
OpenIAM before 4.2.0.3 has Incorrect Access Control for the Create User, Modify User Permissions, and Password Reset actions.
CVE-2020-13420 1 Openiam 1 Openiam 2024-11-21 9.8 Critical
OpenIAM before 4.2.0.3 allows remote attackers to execute arbitrary code via Groovy Script.
CVE-2020-13419 1 Openiam 1 Openiam 2024-11-21 5.3 Medium
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task.
CVE-2020-13418 1 Openiam 1 Openiam 2024-11-21 6.1 Medium
OpenIAM before 4.2.0.3 allows XSS in the Add New User feature.
CVE-2020-13417 4 Apple, Aviatrix, Linux and 1 more 6 Macos, Controller, Gateway and 3 more 2024-11-21 9.8 Critical
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
CVE-2020-13416 1 Aviatrix 1 Controller 2024-11-21 6.5 Medium
An issue was discovered in Aviatrix Controller before 5.4.1066. A Controller Web Interface session token parameter is not required on an API call, which opens the application up to a Cross Site Request Forgery (CSRF) vulnerability for password resets.
CVE-2020-13415 1 Aviatrix 1 Controller 2024-11-21 7.5 High
An issue was discovered in Aviatrix Controller through 5.1. An attacker with any signed SAML assertion from the Identity Provider can establish a connection (even if that SAML assertion has expired or is from a user who is not authorized to access Aviatrix), aka XML Signature Wrapping.
CVE-2020-13414 1 Aviatrix 2 Controller, Gateway 2024-11-21 7.5 High
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by the software.
CVE-2020-13413 1 Aviatrix 2 Controller, Vpn Client 2024-11-21 5.3 Medium
An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force.
CVE-2020-13412 1 Aviatrix 1 Controller 2024-11-21 8.8 High
An issue was discovered in Aviatrix Controller before 5.4.1204. An API call on the web interface lacked a session token check to control access, leading to CSRF.
CVE-2020-13410 1 Aedes Project 1 Aedes 2024-11-21 7.5 High
An issue was discovered in MoscaJS Aedes 0.42.0. lib/write.js does not properly consider exceptions during the writing of an invalid packet to a stream.
CVE-2020-13409 1 Tufin 1 Securetrack 2024-11-21 5.9 Medium
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 3 of 3)
CVE-2020-13408 1 Tufin 1 Securetrack 2024-11-21 5.9 Medium
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 2 of 3)
CVE-2020-13407 1 Tufin 1 Securetrack 2024-11-21 5.9 Medium
Tufin SecureTrack < R20-2 GA contains reflected + stored XSS (as in, the value is reflected back to the user, but is also stored within the DB and can be later triggered again by the same victim, or also later by different users). Both stored, and reflected payloads are triggerable by admin, so malicious non-authenticated user could get admin level access. Even malicious low-privileged user can inject XSS, which can be executed by admin, potentially elevating privileges and obtaining admin access. (issue 1 of 3)
CVE-2020-13405 1 Microweber 1 Microweber 2024-11-21 7.5 High
userfiles/modules/users/controller/controller.php in Microweber before 1.1.20 allows an unauthenticated user to disclose the users database via a /modules/ POST request.
CVE-2020-13404 1 Quadra-informatique 1 Atos\/sips 2024-11-21 8.8 High
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.