|
195111
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access to their profile page via using a specially crafted username.
|
NVD-CWE-noinfo
|
CVE-2021-22231
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195112
|
7.2 |
HIGH
Network
|
gitlab
|
gitlab
|
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and later through 13.11.6, 13.12.6, and 14.0.2.
|
NVD-CWE-noinfo
|
CVE-2021-22230
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195113
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they …
|
CWE-79
Cross-site Scripting
|
CVE-2021-22227
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195114
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions starting from 14.0 before 14.0.2. Improper access contr…
|
NVD-CWE-Other
|
CVE-2021-22228
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195115
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link
|
CWE-79
Cross-site Scripting
|
CVE-2021-22223
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195116
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
|
CWE-74
Injection
|
CVE-2021-22232
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195117
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by…
|
NVD-CWE-noinfo
|
CVE-2021-22229
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195118
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9
|
NVD-CWE-noinfo
|
CVE-2021-22226
|
2024-11-21 14:49 |
2021-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195119
|
5.3 |
MEDIUM
Network
|
huawei
|
magic_ui emui
|
There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause temporary DoS.
|
NVD-CWE-Other
|
CVE-2021-22344
|
2024-11-21 14:49 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195120
|
9.1 |
CRITICAL
Network
|
huawei
|
magic_ui emui
|
There is a Configuration Defect vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service integrity and availability.
|
NVD-CWE-noinfo
|
CVE-2021-22343
|
2024-11-21 14:49 |
2021-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|