Export limit exceeded: 96241 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (96241 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2020-13359 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.6 High |
| The Terraform API in GitLab CE/EE 12.10+ exposed the object storage signed URL on the delete operation allowing a malicious project maintainer to overwrite the Terraform state, bypassing audit and other business controls. Affected versions are >=12.10, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2. | ||||
| CVE-2020-13356 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 8.2 High |
| An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.8.9. A specially crafted request could bypass Multipart protection and read files in certain specific paths on the server. Affected versions are: >=8.8.9, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2. | ||||
| CVE-2020-13355 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14. A path traversal is found in LFS Upload that allows attacker to overwrite certain specific paths on the server. Affected versions are: >=8.14, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2. | ||||
| CVE-2020-13343 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| An issue has been discovered in GitLab affecting all versions starting from 11.2. Unauthorized Users Can View Custom Project Template | ||||
| CVE-2020-13340 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 8.7 High |
| An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log | ||||
| CVE-2020-13337 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.2 High |
| An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name. | ||||
| CVE-2020-13325 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.1 High |
| A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service. | ||||
| CVE-2020-13323 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.7 High |
| A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos | ||||
| CVE-2020-13322 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.2 High |
| A vulnerability was discovered in GitLab versions after 12.9. Due to improper verification of permissions, an unauthorized user can create and delete deploy tokens. | ||||
| CVE-2020-13321 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 8.3 High |
| A vulnerability was discovered in GitLab versions prior to 13.1. Username format restrictions could be bypassed allowing for html tags to be added. | ||||
| CVE-2020-13303 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.1 High |
| A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project. | ||||
| CVE-2020-13300 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 8 High |
| GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow. | ||||
| CVE-2020-13299 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 8.1 High |
| A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The revocation feature was not revoking all session tokens and one could re-use it to obtain a valid session. | ||||
| CVE-2020-13298 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.2 High |
| A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Conan package upload functionality was not properly validating the supplied parameters, which resulted in the limited files disclosure. | ||||
| CVE-2020-13291 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 8.1 High |
| In GitLab before 13.2.3, project sharing could temporarily allow too permissive access. | ||||
| CVE-2020-13290 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.5 High |
| In GitLab before 13.0.12, 13.1.6, and 13.2.3, improper access control was used on the Applications page | ||||
| CVE-2020-13285 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.3 High |
| For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting (XSS) vulnerability exists in the issue reference number tooltip. | ||||
| CVE-2020-13283 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.3 High |
| For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title. | ||||
| CVE-2020-13279 | 1 Gitlab | 1 Gitlab-vscode-extension | 2024-11-21 | 8.6 High |
| Client side code execution in gitlab-vscode-extension v2.2.0 allows attacker to execute code on user system | ||||
| CVE-2020-13276 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 7.4 High |
| User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1 | ||||