|
208451
|
5.3 |
MEDIUM
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2020.2, the built-in web server could expose information about the IDE version.
|
NVD-CWE-noinfo
|
CVE-2020-27622
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208452
|
7.5 |
HIGH
Network
|
anuko
|
time_tracker
|
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-27423
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208453
|
9.8 |
CRITICAL
Network
|
anuko
|
time_tracker
|
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-27422
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208454
|
5.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.1.5, secure dependency parameters could be not masked in depending builds when there are no internal artifacts.
|
NVD-CWE-noinfo
|
CVE-2020-27629
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208455
|
4.3 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2020.1.5, the Guest user had access to audit records.
|
NVD-CWE-noinfo
|
CVE-2020-27628
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208456
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.3.5333 was vulnerable to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-27626
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208457
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2020.3.888, notifications might have mentioned inaccessible issues.
|
NVD-CWE-noinfo
|
CVE-2020-27625
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208458
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
JetBrains YouTrack before 2020.3.888 was vulnerable to SSRF.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2020-27624
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208459
|
6.1 |
MEDIUM
Network
|
chronoengine
|
chronoforums
|
Chronoforeum 2.0.11 allows Stored XSS vulnerabilities when inserting a crafted payload into a post. If any user sees the post, the inserted XSS code is executed.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27459
|
2024-11-21 14:21 |
2020-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208460
|
8.8 |
HIGH
Network
|
flexdotnetcms_project
|
flexdotnetcms
|
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g.,…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2020-27386
|
2024-11-21 14:21 |
2020-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|