6.5

CVSS3.1

CVE-2025-3525 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI trigge…

📅 Published: Feb. 25, 2026, 7:33 p.m. 🔄 Last Modified: Feb. 27, 2026, 4:17 p.m.

6.1

CVSS3.1

CVE-2026-25734 - Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the RSE metadata of the WebUI where attacker…

📅 Published: Feb. 25, 2026, 7:33 p.m. 🔄 Last Modified: April 17, 2026, 3 p.m.

4.3

CVSS3.1

CVE-2025-14103 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.

📅 Published: Feb. 25, 2026, 7:33 p.m. 🔄 Last Modified: Feb. 27, 2026, 4:18 p.m.

8

CVSS3.1

CVE-2026-22720 - VMware Aria Operations stored cross-site scripting vulnerability

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed …

📅 Published: Feb. 25, 2026, 7:33 p.m. 🔄 Last Modified: April 15, 2026, 5 p.m.

7.3

CVSS3.1

CVE-2026-25733 - Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Custom Rules function of the WebUI where…

📅 Published: Feb. 25, 2026, 7:30 p.m. 🔄 Last Modified: April 17, 2026, 3 p.m.

5.3

CVSS3.1

CVE-2026-25138 - Rucio WebUI has Username Enumeration via Login Error Message

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Prior to versions 35.8.3, 38.5.4, and 39.3.1, the WebUI login endpoint returns distinct error messages depending on whether a supplied username exi…

📅 Published: Feb. 25, 2026, 7:28 p.m. 🔄 Last Modified: April 18, 2026, 5:45 p.m.

8.1

CVSS3.1

CVE-2026-22719 - VMware Aria Operations command injection vulnerability

VMware Aria Operations contains a command injection vulnerability. A malicious unauthenticated actor may exploit this issue to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress.  To remediate CVE-202…

📅 Published: Feb. 25, 2026, 7:18 p.m. 🔄 Last Modified: April 15, 2026, 5 p.m.

8.1

CVSS3.1

CVE-2026-25136 - Rucio WebUI has a Reflected Cross-site Scripting Vulnerability

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scripting vulnerability was located in versions prior to 35.8.3, 38.5.4, and 39.3.1 in the rendering of the ExceptionMessage…

📅 Published: Feb. 25, 2026, 6:57 p.m. 🔄 Last Modified: April 17, 2026, 3 p.m.

5.5

CVSS3.1

CVE-2026-2636 - Denial of Service in Microsoft OS

This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger a system crash. Micro…

📅 Published: Feb. 25, 2026, 6:57 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.

0

CVSS3.1

CVE-2026-24005 - OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host Field

Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HTTPGet handlers. The webhook validation does not restrict the Host field in these probe configurations. Since kruise-dae…

📅 Published: Feb. 25, 2026, 6:53 p.m. 🔄 Last Modified: April 18, 2026, 10:45 a.m.
Total resulsts: 349182
Page 1438 of 34,919
« previous page » next page
Filters