|
246311
|
9.8 |
CRITICAL
Network
|
abus
|
tvip_10000_firmware tvip_10001_firmware tvip_10005_firmware tvip_10005a_firmware tvip_10005b_firmware tvip_10050_firmware tvip_10051_firmware tvip_10055a_firmware tvip_10055b_…
|
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050 LM.1.6.18, TVIP10051 LM.1.6.18, TVIP11050 MG.1.6.03.05, TVIP20550 LM…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-17558
|
2024-11-21 12:54 |
2023-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246312
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. blog-viewer has stored XSS during repository browsing, if package.jso…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17537
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246313
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is stored XSS on the merge request page via project import.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17536
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246314
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers could obtain sensitive information about group names, avatars, LDAP setti…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-17455
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246315
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Attackers may have been able to obtain sensitive access-token data fr…
|
NVD-CWE-noinfo
|
CVE-2018-17453
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246316
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via a loopback address to…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-17452
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246317
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Cross Site Request Forgery (CSRF) in the Slack integration f…
|
CWE-352
Origin Validation Error
|
CVE-2018-17451
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246318
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. There is Server-Side Request Forgery (SSRF) via the Kubernetes integr…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-17450
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246319
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. Remote attackers could obtain sensitive information about issues, com…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-17449
|
2024-11-21 12:54 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246320
|
7.5 |
HIGH
Network
|
netwavepr
|
indoor_ip_camera_firmware outdoor_ip_camera_firmware
|
There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., use…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2018-17240
|
2024-11-21 12:54 |
2022-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|