Логотип exploitDog
product: "gitlab"
Консоль
Логотип exploitDog

exploitDog

product: "gitlab"

Количество 5 545

Количество 5 545

nvd логотип

CVE-2021-22227

больше 4 лет назад

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-22227

больше 4 лет назад

A reflected cross-site script vulnerability in GitLab before versions ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22226

больше 4 лет назад

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22226

больше 4 лет назад

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22226

больше 4 лет назад

Under certain conditions, some users were able to push to protected br ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22225

больше 4 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2021-22225

больше 4 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2021-22225

больше 4 лет назад

Insufficient input sanitization in markdown in GitLab version 13.11 an ...

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2021-22224

больше 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2021-22224

больше 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2021-22224

больше 4 лет назад

A cross-site request forgery vulnerability in the GraphQL API in GitLa ...

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22223

больше 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-22223

больше 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-22223

больше 4 лет назад

Client-Side code injection through Feature Flag name in GitLab CE/EE s ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-22221

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-22221

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22221

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-22220

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-22220

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-22220

почти 5 лет назад

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-22227

A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a victim and trigger actions on their behalf if they clicked it

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22227

A reflected cross-site script vulnerability in GitLab before versions ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22226

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22226

Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitLab CE/EE since version 13.9

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22226

Under certain conditions, some users were able to push to protected br ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22225

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22225

Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22225

Insufficient input sanitization in markdown in GitLab version 13.11 an ...

CVSS3: 4.7
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22224

A cross-site request forgery vulnerability in the GraphQL API in GitLa ...

CVSS3: 7.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted feature flag name to PUT requests on behalf of other users via clicking on a link

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22223

Client-Side code injection through Feature Flag name in GitLab CE/EE s ...

CVSS3: 6.1
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13.12.0 before 13.12.2. Insufficient expired password validation in various operations allow user to maintain limited access after their password expired

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22221

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.5
0%
Низкий
почти 5 лет назад
ubuntu логотип
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting with 13.10. GitLab was vulnerable to a stored XSS in blob viewer of notebooks.

CVSS3: 6.1
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2021-22220

An issue has been discovered in GitLab affecting all versions starting ...

CVSS3: 6.1
0%
Низкий
почти 5 лет назад

Уязвимостей на страницу