|
209811
|
6.1 |
MEDIUM
Network
|
zulip
|
zulip_server
|
Zulip Server before 2.1.5 allows reflected XSS via the Dropbox webhook.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12759
|
2024-11-21 14:00 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209812
|
6.1 |
MEDIUM
Network
|
teradici
|
pcoip_management_console
|
Reflected Cross Site Scripting in Teradici PCoIP Management Console prior to 20.07 could allow an attacker to take over the user's active session if the user is exposed to a malicious payload.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13183
|
2024-11-21 14:00 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209813
|
8.8 |
HIGH
Network
|
noviflow
|
noviware
|
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" comma…
|
CWE-78
OS Command
|
CVE-2020-13122
|
2024-11-21 14:00 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209814
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration settings can be modified to result in Server Side Request Forgery.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13286
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209815
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the project import feature
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13281
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209816
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13285
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209817
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13283
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209818
|
3.5 |
LOW
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 after a group transfer occurs, members from a parent group keep their access level on the subgroup leading to improper access.
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-13282
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209819
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
For GitLab before 13.0.12, 13.1.6, 13.2.3 a memory exhaustion flaw exists due to excessive logging of an invite email error message.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-13280
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209820
|
7.5 |
HIGH
Network
|
dovecot debian canonical fedoraproject
|
dovecot debian_linux ubuntu_linux fedora
|
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-12674
|
2024-11-21 14:00 |
2020-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|