Total
796 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2017-20101 | 1 Projectsend | 1 Projectsend | 2024-11-21 | 3.5 Low |
A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely. | ||||
CVE-2017-15211 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user. | ||||
CVE-2017-15209 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user. | ||||
CVE-2017-15208 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private project of another user. | ||||
CVE-2017-15207 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user. | ||||
CVE-2017-15206 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user. | ||||
CVE-2017-15204 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user. | ||||
CVE-2017-15203 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user. | ||||
CVE-2017-15202 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another user. | ||||
CVE-2017-15201 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another user. | ||||
CVE-2017-15200 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of another user. | ||||
CVE-2017-15199 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of another user, as demonstrated by Name, Email, Identifier, and Description. | ||||
CVE-2017-15197 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of another user. | ||||
CVE-2017-15196 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of another user. | ||||
CVE-2017-15195 | 1 Kanboard | 1 Kanboard | 2024-11-21 | N/A |
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user. | ||||
CVE-2017-0936 | 1 Nextcloud | 1 Nextcloud Server | 2024-11-21 | N/A |
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user. | ||||
CVE-2017-0922 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object. | ||||
CVE-2017-0920 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance. | ||||
CVE-2017-0882 | 1 Gitlab | 1 Gitlab | 2024-11-21 | N/A |
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix was included in versions 8.15.8, 8.16.7, and 8.17.4, which were released on March 20th 2017 at 23:59 UTC. | ||||
CVE-2014-8356 | 1 Dasanzhone | 2 Znid 2426a, Znid 2426a Firmware | 2024-11-21 | 8.8 High |
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference. |