|
209761
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.2.8873 is vulnerable to SSRF in the Workflow component.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15823
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209762
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.
|
CWE-276
Incorrect Default Permissions
|
CVE-2020-15821
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209763
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.6881, the markdown parser could disclose hidden file existence.
|
NVD-CWE-noinfo
|
CVE-2020-15820
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209764
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.2.10643 was vulnerable to SSRF that allowed scanning internal ports.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-15819
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209765
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.2.8527, the subtasks workflow could disclose issue existence.
|
NVD-CWE-noinfo
|
CVE-2020-15818
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209766
|
8.8 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
|
NVD-CWE-noinfo
|
CVE-2020-15817
|
2024-11-21 14:06 |
2020-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209767
|
9.8 |
CRITICAL
Network
|
robotemi
|
robox_os
|
Authentication Bypass Using an Alternate Path or Channel in temi Robox OS prior to120, temi Android app up to 1.3.7931 allows remote attackers to gain elevated privileges on the temi and have it auto…
|
CWE-287
Improper Authentication
|
CVE-2020-16169
|
2024-11-21 14:06 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209768
|
9.1 |
CRITICAL
Network
|
robotemi
|
launcher_os
|
Missing Authentication for Critical Function in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to receive and answer calls intended for another temi user. Answeri…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-16167
|
2024-11-21 14:06 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209769
|
6.1 |
MEDIUM
Network
|
mahara
|
mahara
|
In Mahara 19.04 before 19.04.6, 19.10 before 19.10.4, and 20.04 before 20.04.1, certain places could execute file or folder names containing JavaScript.
|
CWE-79
Cross-site Scripting
|
CVE-2020-15907
|
2024-11-21 14:06 |
2020-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209770
|
6.5 |
MEDIUM
Network
|
robotemi
|
temi_firmware
|
Origin Validation Error in temi Robox OS prior to 120, temi Android app up to 1.3.7931 allows remote attackers to access the REST API and MQTT broker used by the temi and send it custom data/requests…
|
CWE-346
Origin Validation Error
|
CVE-2020-16168
|
2024-11-21 14:06 |
2020-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|