|
222421
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipel…
|
NVD-CWE-Other
|
CVE-2019-15591
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222422
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token befor…
|
NVD-CWE-Other
|
CVE-2019-15589
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222423
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head…
|
CWE-200
Information Exposure
|
CVE-2019-15580
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222424
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-15577
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222425
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
|
CWE-862
Missing Authorization
|
CVE-2019-15576
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222426
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
|
CWE-77
Command Injection
|
CVE-2019-15575
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222427
|
9.8 |
CRITICAL
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp allows Insecure File Upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15936
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222428
|
6.1 |
MEDIUM
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15935
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222429
|
8.8 |
HIGH
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15934
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222430
|
9.8 |
CRITICAL
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp has SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2019-15933
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|