|
209771
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions >=10.7 <13.0.14, >=13.1.0 <13.1.8, >=13.2.0 <13.2.6. Improper Access Control for Deploy Tokens
|
CWE-862
Missing Authorization
|
CVE-2020-13296
|
2024-11-21 14:00 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209772
|
7.5 |
HIGH
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity 23.x before 23.3 has improper input validation, leading to a temporary software abort via RTP.
|
CWE-20
Improper Input Validation
|
CVE-2020-12824
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209773
|
5.4 |
MEDIUM
Network
|
fortinet
|
fortitester fortianalyzer
|
An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12815
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209774
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortianalyzer fortimanager
|
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a …
|
CWE-79
Cross-site Scripting
|
CVE-2020-12811
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209775
|
8.1 |
HIGH
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to clickjacking.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2020-13119
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209776
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to malicious file uploads via the form for uploading sounds to garage doors. The magic bytes for WAV must be used.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-12843
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209777
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12842
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209778
|
6.5 |
MEDIUM
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload imae files via /index.php
|
CWE-352
Origin Validation Error
|
CVE-2020-12841
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209779
|
6.5 |
MEDIUM
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to CSRF that allows remote attackers to upload sound files via /index.php
|
CWE-352
Origin Validation Error
|
CVE-2020-12840
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209780
|
9.8 |
CRITICAL
Network
|
gogogate
|
ismartgate_pro_firmware
|
ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12839
|
2024-11-21 14:00 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|