Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2020-05-24 CVE-2020-13433 SQL Injection vulnerability in Adminpanel Project Adminpanel 4.0
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
network
low complexity
adminpanel-project CWE-89
7.5
2020-05-24 CVE-2020-13430 Cross-site Scripting vulnerability in Grafana
Grafana before 7.0.0 allows tag value XSS via the OpenTSDB datasource.
network
low complexity
grafana CWE-79
6.1
2020-05-24 CVE-2020-13429 Cross-site Scripting vulnerability in Grafana Piechart-Panel
legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.
network
grafana CWE-79
3.5
2020-05-23 CVE-2020-13425 Missing Authorization vulnerability in Thetrackr Trackr Firmware 20200506
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
low complexity
thetrackr CWE-862
6.8
2020-05-23 CVE-2020-13424 Information Exposure vulnerability in Xcloner 3.5.1
The XCloner component before 3.5.4 for Joomla! allows Authenticated Local File Disclosure.
network
low complexity
xcloner CWE-200
4.0
2020-05-22 CVE-2020-13417 Unspecified vulnerability in Aviatrix Controller, Gateway and VPN Client
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224.
network
low complexity
aviatrix
7.5
2020-05-22 CVE-2020-13416 Cross-Site Request Forgery (CSRF) vulnerability in Aviatrix Controller
An issue was discovered in Aviatrix Controller before 5.4.1066.
network
aviatrix CWE-352
4.3
2020-05-22 CVE-2020-13415 Improper Verification of Cryptographic Signature vulnerability in Aviatrix Controller
An issue was discovered in Aviatrix Controller through 5.1.
network
low complexity
aviatrix CWE-347
5.0
2020-05-22 CVE-2020-13414 Use of Hard-coded Credentials vulnerability in Aviatrix Controller
An issue was discovered in Aviatrix Controller before 5.4.1204.
network
low complexity
aviatrix CWE-798
5.0
2020-05-22 CVE-2020-13413 Information Exposure Through Discrepancy vulnerability in Aviatrix Controller
An issue was discovered in Aviatrix Controller before 5.4.1204.
network
low complexity
aviatrix CWE-203
5.0