Search Results (323436 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2020-13277 1 Gitlab 1 Gitlab 2024-11-21 6.3 Medium
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
CVE-2020-13276 1 Gitlab 1 Gitlab 2024-11-21 7.4 High
User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1
CVE-2020-13275 1 Gitlab 1 Gitlab 2024-11-21 8 High
A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1
CVE-2020-13274 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
A security issue allowed achieving Denial of Service attacks through memory exhaustion by uploading malicious artifacts in all previous GitLab versions through 13.0.1
CVE-2020-13273 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
A Denial of Service vulnerability allowed exhausting the system resources in GitLab CE/EE 12.0 and later through 13.0.1
CVE-2020-13272 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
OAuth flow missing verification checks CE/EE 12.3 and later through 13.0.1 allows unverified user to use OAuth authorization code flow
CVE-2020-13271 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
CVE-2020-13270 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
CVE-2020-13269 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1
CVE-2020-13268 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1
CVE-2020-13267 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
CVE-2020-13266 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
CVE-2020-13265 1 Gitlab 1 Gitlab 2024-11-21 4.3 Medium
User email verification bypass in GitLab CE/EE 12.5 and later through 13.0.1 allows user to bypass email verification
CVE-2020-13264 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
Kubernetes cluster token disclosure in GitLab CE/EE 10.3 and later through 13.0.1 allows other group maintainers to view Kubernetes cluster token
CVE-2020-13263 1 Gitlab 1 Gitlab 2024-11-21 7.5 High
An authorization issue relating to project maintainer impersonation was identified in GitLab EE 9.5 and later through 13.0.1 that could allow unauthorized users to impersonate as a maintainer to perform limited actions.
CVE-2020-13262 1 Gitlab 1 Gitlab 2024-11-21 6.1 Medium
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
CVE-2020-13261 1 Gitlab 1 Gitlab 2024-11-21 5.3 Medium
Amazon EKS credentials disclosure in GitLab CE/EE 12.6 and later through 13.0.1 allows other administrators to view Amazon EKS credentials via HTML source code
CVE-2020-13260 1 Rad 2 Secflow-1v, Secflow-1v Firmware 2024-11-21 6.1 Medium
A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in Configuration-Services-Security-OpenVPN-Static Keys. This payload will execute each time a user opens an affected web page. This could be exploited in conjunction with CVE-2020-13259.
CVE-2020-13259 1 Rad 2 Secflow-1v, Secflow-1v Firmware 2024-11-21 8.8 High
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protections for the web UI on an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to follow a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. This could be exploited in conjunction with CVE-2020-13260.
CVE-2020-13258 1 Contentful 1 Python Example 2024-11-21 6.1 Medium
Contentful through 2020-05-21 for Python allows reflected XSS, as demonstrated by the api parameter to the-example-app.py.