Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 336

Количество 5 336

ubuntu логотип

CVE-2025-1908

10 месяцев назад

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-1908

10 месяцев назад

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
EPSS: Низкий
debian логотип

CVE-2025-1908

10 месяцев назад

An issue has been discovered in GitLab EE/CE that could allow an attac ...

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2025-1763

9 месяцев назад

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-1763

9 месяцев назад

An issue has been discovered in GitLab EE that allows for cross-site-s ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-1754

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-1754

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-1754

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-1677

10 месяцев назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-1677

10 месяцев назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-1677

10 месяцев назад

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE af ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-1540

11 месяцев назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2025-1540

11 месяцев назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2025-1540

11 месяцев назад

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedi ...

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2025-1516

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-1516

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-1516

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-1478

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-1478

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-1478

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-1908

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-1908

An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 7.7
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-1908

An issue has been discovered in GitLab EE/CE that could allow an attac ...

CVSS3: 7.7
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-1763

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

CVSS3: 8.7
0%
Низкий
9 месяцев назад
debian логотип
CVE-2025-1763

An issue has been discovered in GitLab EE that allows for cross-site-s ...

CVSS3: 8.7
0%
Низкий
9 месяцев назад
ubuntu логотип
CVE-2025-1754

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-1754

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to resource abuse and unauthorized content storage.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-1754

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 5.3
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-1677

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-1677

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all up to 17.8.7, 17.9 prior to 17.9.6 and 17.10 prior to 17.10.4 A denial of service could occur upon injecting oversized payloads into CI pipeline exports.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-1677

A Denial of Service (DoS) issue has been discovered in GitLab CE/EE af ...

CVSS3: 6.5
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS3: 3.1
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-1540

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedi ...

CVSS3: 3.1
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-1516

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-1516

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-1516

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2025-1478

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2025-1478

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2025-1478

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу