|
210471
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections…
|
CWE-89
SQL Injection
|
CVE-2020-13501
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210472
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections re…
|
CWE-89
SQL Injection
|
CVE-2020-13500
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210473
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections…
|
CWE-89
SQL Injection
|
CVE-2020-13499
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210474
|
2.7 |
LOW
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. A user without 2 factor authentication enabled could be prohibited from accessing GitLab by being invited into a p…
|
CWE-281
Improper Preservation of Permissions
|
CVE-2020-13308
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210475
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a …
|
NVD-CWE-noinfo
|
CVE-2020-13315
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210476
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab runner versions before 13.1.3, 13.2.3 and 13.3.1. It was possible to make the gitlab-runner process crash by sending malformed queries, resulting in a denial …
|
NVD-CWE-noinfo
|
CVE-2020-13310
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210477
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was vulnerable to a blind SSRF attack through the repository mirroring feature.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13309
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210478
|
4.9 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8, and 13.3.4. An insufficient check in the GraphQL api allowed a maintainer to delete a repository.
|
CWE-20
Improper Input Validation
|
CVE-2020-13317
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210479
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error …
|
NVD-CWE-Other
|
CVE-2020-13314
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210480
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. An unauthorized project maintainer could edit the subgroup badges due to the lack of authorization control.
|
CWE-863
Incorrect Authorization
|
CVE-2020-13313
|
2024-11-21 14:01 |
2020-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|