|
218381
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, access grants were not revoked when a user revoked access to an application.
|
NVD-CWE-noinfo
|
CVE-2020-13294
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218382
|
7.1 |
HIGH
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3 using a branch with a hexadecimal name could override an existing hash.
|
NVD-CWE-noinfo
|
CVE-2020-13293
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218383
|
9.6 |
CRITICAL
Network
|
gitlab
|
gitlab
|
In GitLab before 13.0.12, 13.1.6 and 13.2.3, it is possible to bypass E-mail verification which is required for OAuth Flow.
|
CWE-287
Improper Authentication
|
CVE-2020-13292
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218384
|
8.8 |
HIGH
Network
|
combodo
|
itop
|
Combodo iTop contains a cross-site request forgery (CSRF) vulnerability, attackers can execute specific commands via malicious site request forgery.
|
CWE-352
Origin Validation Error
|
CVE-2020-12781
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218385
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A security misconfiguration exists in Combodo iTop, which can expose sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12780
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218386
|
5.4 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop contains a stored Cross-site Scripting vulnerability, which can be attacked by uploading file with malicious script.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12779
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218387
|
6.1 |
MEDIUM
Network
|
combodo
|
itop
|
Combodo iTop does not validate inputted parameters, attackers can inject malicious commands and launch XSS attack.
|
CWE-79
Cross-site Scripting
|
CVE-2020-12778
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218388
|
7.5 |
HIGH
Network
|
combodo
|
itop
|
A function in Combodo iTop contains a vulnerability of Broken Access Control, which allows unauthorized attacker to inject command and disclose system information.
|
CWE-200
Information Exposure
|
CVE-2020-12777
|
2024-11-21 14:00 |
2020-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218389
|
9.8 |
CRITICAL
Network
|
aerospike
|
aerospike_server
|
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code exe…
|
CWE-78
OS Command
|
CVE-2020-13151
|
2024-11-21 14:00 |
2020-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218390
|
5.3 |
MEDIUM
Network
|
fanuc
|
series_30i_firmware series_31i_firmware series_32i-b_plus_firmware series_35i-b_firmware power_motion_i-model_a_firmware series_0i-model_f_plus_firmware series_0i-model_f_firmware
|
A denial-of-service vulnerability in the Fanuc i Series CNC (0i-MD and 0i Mate-MD) could allow an unauthenticated, remote attacker to cause an affected CNC to become inaccessible to other devices.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2020-12739
|
2024-11-21 14:00 |
2020-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|