|
213681
|
7.2 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens.
|
CWE-863
Incorrect Authorization
|
CVE-2020-13322
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213682
|
8.3 |
HIGH
Network
|
gitlab
|
gitlab
|
A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added.
|
NVD-CWE-noinfo
|
CVE-2020-13321
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213683
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab before version 12.10.13 that allowed a project member with limited permissions to view the project security dashboard.
|
NVD-CWE-noinfo
|
CVE-2020-13320
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213684
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.
|
CWE-862
Missing Authorization
|
CVE-2020-13319
|
2024-11-21 14:01 |
2020-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213685
|
7.5 |
HIGH
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 23.4 has a lack of input validation, leading to temporary denial of service via H.323.
|
CWE-20
Improper Input Validation
|
CVE-2020-13387
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213686
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker …
|
CWE-89
SQL Injection
|
CVE-2020-13505
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213687
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An at…
|
CWE-89
SQL Injection
|
CVE-2020-13504
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213688
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections…
|
CWE-89
SQL Injection
|
CVE-2020-13501
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213689
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections re…
|
CWE-89
SQL Injection
|
CVE-2020-13500
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213690
|
9.8 |
CRITICAL
Network
|
aveva
|
edna_enterprise_data_historian
|
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections…
|
CWE-89
SQL Injection
|
CVE-2020-13499
|
2024-11-21 14:01 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|