|
222971
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition through 12.2.1. Embedded images and media files in markdown could be pointed to an arbitrary server, which would reveal the IP addre…
|
NVD-CWE-noinfo
|
CVE-2019-15726
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222972
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. An IDOR in the epic notes API that could result in disclosure of private milestones, labels, and other informat…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2019-15725
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222973
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15724
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222974
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.9.x and 11.10.x before 11.10.1. Merge requests created by email could be used to bypass push rules in certain situations.
|
CWE-862
Missing Authorization
|
CVE-2019-15723
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222975
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.2.1. Particular mathematical expressions in GitLab Markdown can exhaust client resources.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2019-15722
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222976
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainers to view and edit group runner settings.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2019-15721
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222977
|
6.1 |
MEDIUM
Network
|
redmineup
|
crm
|
The CRM Plugin before 4.2.4 for Redmine allows XSS via crafted vCard data.
|
CWE-79
Cross-site Scripting
|
CVE-2019-15950
|
2024-11-21 13:29 |
2019-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222978
|
9.8 |
CRITICAL
Network
|
dlink
|
dns-320_firmware
|
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
|
CWE-78
OS Command
|
CVE-2019-16057
|
2024-11-21 13:29 |
2019-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222979
|
9.8 |
CRITICAL
Network
|
lifterlms
|
lifterlms
|
An issue was discovered in the LifterLMS plugin through 3.34.5 for WordPress. The upload_import function in the class.llms.admin.import.php script is prone to an unauthenticated options import vulner…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15896
|
2024-11-21 13:29 |
2019-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222980
|
7.5 |
HIGH
Network
|
search_exclude_project
|
search_exclude
|
search-exclude.php in the "Search Exclude" plugin before 1.2.4 for WordPress allows unauthenticated options changes.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2019-15895
|
2024-11-21 13:29 |
2019-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|