Exploit Database

149,752 exploits tracked across all sources.

Sort: Activity Stars
CVE-2020-26407 WRITEUP MEDIUM
GitLab 12.4-13.4.6, 13.5-13.5.4, 13.6-13.6.1 - Stored Cross-Site Scripting via Malicious Project Import
A XSS vulnerability exists in Gitlab CE/EE from 12.4 before 13.4.7, 13.5 before 13.5.5, and 13.6 before 13.6.2 that allows an attacker to perform cross-site scripting to other users via importing a malicious project
CVSS 5.5
CVE-2020-26408 WRITEUP MEDIUM
GitLab 12.2.0-13.4.6, 13.5.0-13.5.4, 13.6.0-13.6.1 - Limited Information Disclosure in Private Profile
A limited information disclosure vulnerability exists in Gitlab CE/EE from >= 12.2 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2 that allows an attacker to view limited information in user's private profile
CVSS 5.3
CVE-2020-26411 WRITEUP MEDIUM
Gitlab <13.4.7, <13.5.5, <13.6.2 - DoS
A potential DOS vulnerability was discovered in all versions of Gitlab starting from 13.4.x (>=13.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2). Using a specific query name for a project search can cause statement timeouts that can lead to a potential DOS if abused.
CVSS 4.3
CVE-2020-26414 WRITEUP MEDIUM
GitLab 12.4.0-13.5.5 - Denial of Service via Malicious Package Name Input
An issue has been discovered in GitLab affecting all versions starting from 12.4. The regex used for package names is written in a way that makes execution time have quadratic growth based on the length of the malicious input string.
CVSS 4.3
CVE-2020-26416 WRITEUP MEDIUM
GitLab 8.4.0-13.4.6 13.5.0-13.5.4 13.6.0-13.6.1 - Information Disclosure in Advanced Search
Information disclosure in Advanced Search component of GitLab EE starting from 8.4 results in exposure of search terms via Rails logs. This affects versions >=8.4 to <13.4.7, >=13.5 to <13.5.5, and >=13.6 to <13.6.2.
CVSS 4.0
CVE-2020-26418 WRITEUP LOW
Wireshark <3.4.0, 3.2.0-3.2.8 - DoS
Memory leak in Kafka protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVSS 3.1
CVE-2020-26419 WRITEUP LOW
Wireshark 3.4.0 - Denial of Service via Memory Leak in Dissection Engine
Memory leak in the dissection engine in Wireshark 3.4.0 allows denial of service via packet injection or crafted capture file.
CVSS 3.1
CVE-2020-26420 WRITEUP LOW
Wireshark <3.4.0, 3.2.0-3.2.8 - DoS
Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVSS 3.1
CVE-2020-26421 WRITEUP MEDIUM
Wireshark <3.4.0, 3.2.0-3.2.8 - DoS
Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVSS 4.2
CVE-2020-26422 WRITEUP LOW
Wireshark 3.4.0-3.4.1 - Denial of Service via QUIC Dissector Buffer Overflow
Buffer overflow in QUIC dissector in Wireshark 3.4.0 to 3.4.1 allows denial of service via packet injection or crafted capture file
CVSS 3.7
CVE-2020-26575 WRITEUP HIGH
Wireshark < 3.2.7 - Denial of Service via Infinite Loop in FBZERO Dissector
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
CVSS 7.5
CVE-2020-28030 WRITEUP HIGH
Wireshark 3.2.0-3.2.7 - Denial of Service in GQUIC Dissector
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
CVSS 7.5
CVE-2020-35523 WRITEUP HIGH
libtiff < 4.2.0 - Integer Overflow in tif_getimage.c
An integer overflow flaw was found in libtiff that exists in the tif_getimage.c file. This flaw allows an attacker to inject and execute arbitrary code when a user opens a crafted TIFF file. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS 7.8
CVE-2020-35524 WRITEUP HIGH
libtiff < 4.2.0 - Heap-Based Buffer Overflow in TIFF2PDF Tool
A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVSS 7.8
CVE-2020-36541 WRITEUP HIGH
demokratian - SQL Injection via id_provincia Parameter in basicos_php/genera_select.php
A vulnerability was found in Demokratian. It has been rated as critical. Affected by this issue is some unknown functionality of the file basicos_php/genera_select.php. The manipulation of the argument id_provincia with the input -1%20union%20all%20select%201,2,3,4,database() leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
CVSS 7.3
CVE-2020-36542 WRITEUP HIGH
demokratian - Privilege Escalation in install/install3.php
A vulnerability classified as critical has been found in Demokratian. This affects an unknown part of the file install/install3.php. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
CVSS 7.3
CVE-2020-8933 WRITEUP HIGH
Google guest-oslogin 20190304-20200507 - Privilege Escalation via lxd Group Membership
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it is possible to attach the host OS filesystem and modify /etc/sudoers to then gain administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "lxd" user from the OS Login entry.
CVSS 7.8
CVE-2020-8907 WRITEUP HIGH
Google guest-oslogin 20190304-20200507 - Privilege Escalation via Docker Group Membership
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacker with this role is able to run docker and mount the host OS. Within docker, it is possible to modify the host OS filesystem and modify /etc/groups to gain administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "docker" user from the OS Login entry.
CVSS 7.8
CVE-2020-8903 WRITEUP HIGH
Google guest-oslogin 20190304-20200507 - Privilege Escalation via DHCP XID Manipulation
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal. Using the DHCP XID, it is then possible to set the IP address and hostname of the instance to any value, which is then stored in /etc/hosts. An attacker can then point metadata.google.internal to an arbitrary IP address and impersonate the GCE metadata server which make it is possible to instruct the OS Login PAM module to grant administrative privileges. All images created after 2020-May-07 (20200507) are fixed, and if you cannot update, we recommend you edit /etc/group/security.conf and remove the "adm" user from the OS Login entry.
CVSS 7.8
CVE-2020-25105 WRITEUP CRITICAL
eramba c2.8.1 and Enterprise < e2.19.3 - Weak Password Recovery Token
eramba c2.8.1 and Enterprise before e2.19.3 has a weak password recovery token (createHash has only a million possibilities).
CVSS 9.8
CVE-2020-25104 WRITEUP MEDIUM
eramba c2.8.1 and Enterprise < e2.19.3 - Stored Cross-Site Scripting via Attached Filename
eramba c2.8.1 and Enterprise before e2.19.3 allows XSS via a crafted filename for a file attached to an object. For example, the filename has a complete XSS payload followed by the .png extension.
CVSS 5.4
CVE-2019-19604 WRITEUP HIGH
Git <2.20.2-2.24.1 - Command Injection
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVSS 7.8
CVE-2021-20286 WRITEUP LOW
libnbd < 1.7.3 - Denial of Service via Assertion Failure in nbd_unlocked_opt_go
A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service.
CVSS 2.7
CVE-2021-22166 WRITEUP MEDIUM
GitLab 13.7.0-13.7.1 - Denial of Service via Malformed HTTP Method
An attacker could cause a Prometheus denial of service in GitLab 13.7+ by sending an HTTP request with a malformed method
CVSS 5.3
CVE-2021-22170 WRITEUP MEDIUM
GitLab 11.6.0-13.5.5 - Use of a Broken or Risky Cryptographic Algorithm
Assuming a database breach, nonce reuse issues in GitLab 11.6+ allows an attacker to decrypt some of the database's encrypted content
CVSS 6.2