7.5

CVSS3.1

CVE-2025-14513 - Improper Validation of Specified Quantity in Input in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due to improper input validation when processing specially crafted JSON p…

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

4.3

CVSS3.1

CVE-2026-0602 - Authentication Bypass Using an Alternate Path or Channel in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues, merge requests, epics, milestones, or commits due to improper filtering i…

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 23, 2026, 9:55 a.m.

7.5

CVSS3.1

CVE-2026-1069 - Uncontrolled Recursion in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by sending specially crafted GraphQL requests due to uncontrolled recursion under certain circumstances.

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

8.7

CVSS3.1

CVE-2026-1090 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanit…

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

4.1

CVSS3.1

CVE-2026-1230 - Use of Incorrectly-Resolved Name or Reference in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 1.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause repository downloads to contain different code than displayed in the web interface due to incorrect validat…

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

4.3

CVSS3.1

CVE-2026-1663 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with group import permissions to create labels in private projects due to improper authorization validation in the …

πŸ“… Published: March 11, 2026, 4:04 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-30234 - OpenProject BIM BCF XML Import: <Snapshot> Path Traversal Leads to Arbitrary Local File Read (AFR)

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions can upload a crafted .bcf archive where the <Snapshot> value in markup.bcf is manipulated to contain an absolute or traversal local path (for example: /…

πŸ“… Published: March 11, 2026, 3:59 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

6.1

CVSS4.0

CVE-2026-29777 - Traefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deployments, this can bypa…

πŸ“… Published: March 11, 2026, 3:54 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-28803 - Open Forms possible to view submission details of other people than intended

Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instructions or a deep-link to start the cosign flow. The submission reference is communicated so that the user can retrieve the submission to be cosigned. A…

πŸ“… Published: March 11, 2026, 3:52 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

2

CVSS4.0

CVE-2026-1497 - Incorrect privilege assignment in composite databases

Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:Β  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently grant access to any loc…

πŸ“… Published: March 11, 2026, 3:50 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.
Total resulsts: 347398
Page 1003 of 34,740
Β« previous page Β» next page
Filters