Search Results (322820 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-13483 1 Bitrix24 1 Bitrix24 2024-11-21 6.1 Medium
The Web Application Firewall in Bitrix24 through 20.0.0 allows XSS via the items[ITEMS][ID] parameter to the components/bitrix/mobileapp.list/ajax.php/ URI.
CVE-2020-13482 3 Em-http-request Project, Fedoraproject, Redhat 3 Em-http-request, Fedora, Openstack-optools 2024-11-21 7.4 High
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
CVE-2020-13480 1 Verint 1 Workforce Optimization 2024-11-21 5.4 Medium
Verint Workforce Optimization (WFO) 15.2 allows HTML injection via the "send email" feature.
CVE-2020-13476 1 Nchsoftware 1 Express Invoice 2024-11-21 4.8 Medium
NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
CVE-2020-13474 1 Nchsoftware 1 Express Accounts 2024-11-21 6.5 Medium
In NCH Express Accounts 8.24 and earlier, an authenticated low-privilege user can enter a crafted URL to access higher-privileged functionalities such as Add/Edit users.
CVE-2020-13473 1 Nchsoftware 1 Express Accounts 2024-11-21 5.5 Medium
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
CVE-2020-13472 1 Gigadevice 2 Gd32f103, Gd32f103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in Gigadevice GD32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the DMA module.
CVE-2020-13471 1 Apexmic 2 Apm32f103, Apm32f103 Firmware 2024-11-21 6.8 Medium
Apex Microelectronics APM32F103 devices allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVE-2020-13470 1 Gigadevice 4 Gd32f103, Gd32f103 Firmware, Gd32f130 and 1 more 2024-11-21 4.6 Medium
Gigadevice GD32F103 and GD32F130 devices allow physical attackers to extract data via the probing of easily accessible bonding wires and de-obfuscation of the observed data.
CVE-2020-13469 1 Gigadevice 2 Gd32vf103, Gd32vf103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in Gigadevice GD32VF103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU.
CVE-2020-13468 1 Gigadevice 2 Gd32f130, Gd32f130 Firmware 2024-11-21 6.8 Medium
Gigadevice GD32F130 devices allow physical attackers to escalate their debug interface permissions via fault injection into inter-IC bonding wires (which have insufficient physical protection).
CVE-2020-13467 1 Cksic 2 Cks32f103, Cks32f103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
CVE-2020-13466 1 St 2 Stm32f103, Stm32f103 Firmware 2024-11-21 6.8 Medium
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash patch/breakpoint unit configuration.
CVE-2020-13465 1 Gigadevice 2 Gd32f103, Gd32f103 Firmware 2024-11-21 6.8 Medium
The security protection in Gigadevice GD32F103 devices allows physical attackers to redirect the control flow and execute arbitrary code via the debug interface.
CVE-2020-13464 1 Cksic 2 Cks32f103, Cks32f103 Firmware 2024-11-21 4.2 Medium
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.
CVE-2020-13463 1 Apexmic 2 Apm32f103, Apm32f103 Firmware 2024-11-21 4.6 Medium
The flash memory readout protection in Apex Microelectronics APM32F103 devices allows physical attackers to extract firmware via the debug interface and exception handling.
CVE-2020-13462 1 Tufin 1 Securetrack 2024-11-21 5.7 Medium
Insecure Direct Object Reference (IDOR) exists in Tufin SecureChange, affecting all versions prior to R20-2 GA. Fixed in version R20-2 GA.
CVE-2020-13461 1 Tufin 1 Securetrack 2024-11-21 4.3 Medium
Username enumeration in present in Tufin SecureTrack. It's affecting all versions of SecureTrack. The vendor has decided not to fix this vulnerability. Vendor's response: "This attack requires access to the internal network. If an attacker is part of the internal network, they do not require access to TOS to know the usernames".
CVE-2020-13460 1 Tufin 1 Securetrack 2024-11-21 8.8 High
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities were present in Tufin SecureTrack, affecting all versions prior to R20-2 GA.
CVE-2020-13459 1 Verbb 1 Image Resizer 2024-11-21 5.4 Medium
An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There is stored XSS in the Bulk Resize action.