|
209831
|
6.1 |
MEDIUM
Network
|
teradici
|
pcoip_management_console
|
The web server in the Teradici Managament console versions 20.04 and 20.01.1 did not properly set the X-Frame-Options HTTP header, which could allow an attacker to trick a user into clicking a malici…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-13174
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209832
|
8.8 |
HIGH
Network
|
sabnzbd
|
sabnzbd
|
SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operat…
|
CWE-78
OS Command
|
CVE-2020-13124
|
2024-11-21 14:00 |
2020-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209833
|
8.8 |
HIGH
Network
|
gitlab
|
runner
|
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-13295
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209834
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
|
NVD-CWE-noinfo
|
CVE-2020-13294
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209835
|
7.1 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
|
NVD-CWE-noinfo
|
CVE-2020-13293
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209836
|
9.6 |
CRITICAL
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
|
CWE-287
Improper Authentication
|
CVE-2020-13292
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209837
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
|
CWE-352
Origin Validation Error
|
CVE-2020-12781
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209838
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12780
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209839
|
5.4 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12779
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209840
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12778
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|