• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2020-13431
2021-07-21
N/A
7.8 HIGH
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
CVE-2020-13430
2020-05-28
N/A
6.1 MEDIUM
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
CVE-2020-1343
2021-07-21
N/A
5.9 MEDIUM
An information disclosure vulnerability exists in Visual Studio Code Live Share Extension when it exposes tokens in plain text, aka 'Visual Studio Code Live Share Information Disclosure Vulnerability'.
CVE-2020-13429
2020-05-26
N/A
5.4 MEDIUM
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
CVE-2020-13428
Videolan, Vlc Media Player
Vlc_media_player
2020-06-19
N/A
7.8 HIGH
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
CVE-2020-13427
2020-06-25
N/A
6.1 MEDIUM
Victor CMS 1.0 has Persistent XSS in admin/users.php?source=add_user via the user_name, user_firstname, or user_lastname parameter.
CVE-2020-13426
2020-06-26
N/A
6.5 MEDIUM
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
CVE-2020-13425
2020-05-26
N/A
7.1 HIGH
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
CVE-2020-13424
2021-07-21
N/A
6.5 MEDIUM
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
CVE-2020-13423
2020-07-02
N/A
4.8 MEDIUM
Form Builder 2.1.0 for Magento has multiple XSS issues that can be exploited against Magento 2 admin accounts via the Current_url or email field, or the User-Agent HTTP header.
« Previous 1 … 4,632 4,633 4,634 4,635 4,636 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE