Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 544

Количество 5 544

nvd логотип

CVE-2025-10569

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-10569

3 месяца назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-10497

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-10497

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-10497

5 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-1042

около 1 года назад

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2025-1042

около 1 года назад

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2025-1042

около 1 года назад

An insecure direct object reference vulnerability in GitLab EE affecti ...

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2025-10094

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-10094

7 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2025-10004

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-10004

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-10004

6 месяцев назад

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-0993

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-0993

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-0993

11 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-0811

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2025-0811

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
EPSS: Низкий
debian логотип

CVE-2025-0811

около 1 года назад

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
EPSS: Низкий
ubuntu логотип

CVE-2025-0765

8 месяцев назад

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-10569

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

CVSS3: 6.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-10569

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 6.5
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2025-10497

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-10497

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an unauthenticated attacker to cause a denial of service condition by sending specially crafted payloads.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-10497

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2025-1042

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

CVSS3: 4.9
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-1042

An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to view repositories in an unauthorized way.

CVSS3: 4.9
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-1042

An insecure direct object reference vulnerability in GitLab EE affecti ...

CVSS3: 4.9
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-10094

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to disrupt access to token listings and related administrative operations by creating tokens with excessively large names.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-10094

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 6.5
0%
Низкий
7 месяцев назад
ubuntu логотип
CVE-2025-10004

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-10004

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.12 to 18.2.8, 18.3 to 18.3.4, and 18.4 to 18.4.2 that could make the GitLab instance unresponsive or severely degraded by sending crafted GraphQL queries requesting large repository blobs.

CVSS3: 7.5
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-10004

GitLab has remediated an issue in GitLab CE/EE affecting all versions ...

CVSS3: 7.5
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-0993

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-0993

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. This could allow an authenticated attacker to cause a denial of service condition by exhausting server resources.

CVSS3: 7.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-0993

An issue has been discovered in GitLab CE/EE affecting all versions be ...

CVSS3: 7.5
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2025-0811

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-0811

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

CVSS3: 8.7
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-0811

An issue has been discovered in GitLab CE/EE affecting all versions fr ...

CVSS3: 8.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2025-0765

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.

CVSS3: 4.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу