Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

nvd логотип

CVE-2025-9222

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-9222

около 1 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-8770

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-8770

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-8770

6 месяцев назад

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-8405

2 месяца назад

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-8405

2 месяца назад

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-8405

2 месяца назад

GitLab has remediated a security issue in GitLab CE/EE affecting all v ...

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-8014

5 месяцев назад

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-8014

5 месяцев назад

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-7739

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-7739

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-7739

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-7736

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-7736

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-7736

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2025-7734

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-7734

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-7734

6 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-7691

5 месяцев назад

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-9222

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-9222

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 8.7
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2025-8770

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-8770

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-8770

An issue has been discovered in GitLab EE affecting all versions from ...

CVSS3: 6.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-8405

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 7.7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-8405

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.

CVSS3: 7.7
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-8405

GitLab has remediated a security issue in GitLab CE/EE affecting all v ...

CVSS3: 7.7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-8014

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 allows unauthenticated users to potentially bypass query complexity limits leading to resource exhaustion and service disruption.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-8014

Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-7739

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-7739

An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-7739

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authenticating through OAuth providers.

CVSS3: 3.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 3.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-7734

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-7734

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

CVSS3: 8.7
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-7734

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-7691

A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1 that could have allowed a developer with specific group management permissions to escalate their privileges and obtain unauthorized access to additional system capabilities.

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу