|
223841
|
7.5 |
HIGH
Network
|
statics-server_project
|
statics-server
|
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
|
CWE-22
Path Traversal
|
CVE-2019-15596
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223842
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipel…
|
NVD-CWE-Other
|
CVE-2019-15591
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223843
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token befor…
|
NVD-CWE-Other
|
CVE-2019-15589
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223844
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when using the blocking merge request feature, it was possible for an unauthenticated user to see the head…
|
CWE-200
Information Exposure
|
CVE-2019-15580
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223845
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed project milestones to be disclosed via groups browsing.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2019-15577
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223846
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An information disclosure vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to view private system notes from a GraphQL endpoint.
|
CWE-862
Missing Authorization
|
CVE-2019-15576
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223847
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
|
CWE-77
Command Injection
|
CVE-2019-15575
|
2024-11-21 13:29 |
2019-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223848
|
9.8 |
CRITICAL
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp allows Insecure File Upload.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2019-15936
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223849
|
6.1 |
MEDIUM
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15935
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223850
|
8.8 |
HIGH
Network
|
intesync
|
solismed
|
Intesync Solismed 3.3sp has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2019-15934
|
2024-11-21 13:29 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|