|
210821
|
9.6 |
CRITICAL
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
|
CWE-287
Improper Authentication
|
CVE-2020-13292
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210822
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
|
CWE-352
Origin Validation Error
|
CVE-2020-12781
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210823
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12780
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210824
|
5.4 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12779
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210825
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12778
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210826
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.
|
CWE-200
Information Exposure
|
CVE-2020-12777
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210827
|
9.8 |
CRITICAL
Network
|
aerospike
|
aerospike_server
|
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code exe…
|
CWE-78
OS Command
|
CVE-2020-13151
|
2024-11-21 14:00 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210828
|
5.3 |
MEDIUM
Network
|
fanuc
|
series_30i_firmware series_31i_firmware series_32i-b_plus_firmware series_35i-b_firmware power_motion_i-model_a_firmware series_0i-model_f_plus_firmware series_0i-model_f_firmware
|
A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-12739
|
2024-11-21 14:00 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210829
|
7.5 |
HIGH
Network
|
cherokee-project
|
cherokee
|
Cherokee 0.4.27 to 1.2.104 is affected by a denial of service due to a NULL pointer dereferences. A remote unauthenticated attacker can crash the server by sending an HTTP request to protected resour…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-12845
|
2024-11-21 14:00 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210830
|
5.5 |
MEDIUM
Local
|
pulsesecure ivanti
|
pulse_connect_secure connect_secure pulse_policy_secure policy_secure
|
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping in…
|
NVD-CWE-noinfo
|
CVE-2020-12880
|
2024-11-21 14:00 |
2020-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|