|
210451
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 12.10.13, 13.0.8, 13.1.2. A stored cross-site scripting vulnerability was discovered when editing references.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13338
|
2024-11-21 14:01 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210452
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13337
|
2024-11-21 14:01 |
2020-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210453
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions from 11.8 before 12.10.13. GitLab was vulnerable to a stored XSS by in the error tracking feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13336
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210454
|
4.3 |
MEDIUM
Network
|
linuxfoundation
|
harbor
|
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
|
CWE-862
Missing Authorization
|
CVE-2020-13794
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210455
|
8.0 |
HIGH
Network
|
lansweeper
|
lansweeper
|
In Lansweeper 8.0.130.17, the web console is vulnerable to a CSRF attack that would allow a low-level Lansweeper user to elevate their privileges within the application.
|
CWE-352
Origin Validation Error
|
CVE-2020-13658
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210456
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the Wiki pasges.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13331
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210457
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13330
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210458
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions from 12.6.2 prior to 12.10.13. GitLab was vulnerable to a stored XSS by in the blob view feature.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13329
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210459
|
4.8 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. GitLab was vulnerable to a stored XSS by using the PyPi files API.
|
CWE-79
Cross-site Scripting
|
CVE-2020-13328
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210460
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.
|
NVD-CWE-noinfo
|
CVE-2020-13326
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|