5.5

CVSS3.1

CVE-2026-35339 - uutils coreutils chmod False Success Exit Code in Recursive Mode

The recursive mode (-R) of the chmod utility in uutils coreutils incorrectly handles exit codes when processing multiple files. The final return value is determined solely by the success or failure of the last file processed. This allows the command to return an exit code of 0 (success) even if err…

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: April 27, 2026, 7:54 p.m.

7.3

CVSS3.1

CVE-2026-35338 - uutils coreutils chmod Path Traversal Bypass of --preserve-root

A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validates if the target path is literally / and does not canonicalize the path. An attacker or accidental user can use path variants such as /../ or symbolic…

πŸ“… Published: April 22, 2026, 4:07 p.m. πŸ”„ Last Modified: April 27, 2026, 12:28 p.m.

6.5

CVSS3.1

CVE-2025-0186 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service under certain conditions by exhausting server resources by making crafted requests t…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:51 p.m.

6.5

CVSS3.1

CVE-2025-3922 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.4 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service by overwhelming system resources under certain conditions due to insufficient resour…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:50 p.m.

6.5

CVSS3.1

CVE-2025-6016 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that could have allowed an authenticated user to cause denial of service due to insufficient resource allocation limits when retrieving notes under certain co…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:49 p.m.

2.7

CVSS3.1

CVE-2025-9957 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to imprope…

πŸ“… Published: April 22, 2026, 4:05 p.m. πŸ”„ Last Modified: April 23, 2026, 8:46 p.m.

6.5

CVSS3.1

CVE-2026-1660 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.3 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to cause denial of service when importing issues due to improper input validation.

πŸ“… Published: April 22, 2026, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 8:45 p.m.

8

CVSS3.1

CVE-2026-5262 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input va…

πŸ“… Published: April 22, 2026, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 8:38 p.m.

4.3

CVSS3.1

CVE-2026-5377 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that could have allowed an authenticated user to access titles of confidential or private issues in public projects due to improper access control in the issue description rendering process.

πŸ“… Published: April 22, 2026, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 8:37 p.m.

8

CVSS3.1

CVE-2026-5816 - Improper Resolution of Path Equivalence in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

πŸ“… Published: April 22, 2026, 4:04 p.m. πŸ”„ Last Modified: April 23, 2026, 8:30 p.m.
Total resulsts: 347806
Page 184 of 34,781
Β« previous page Β» next page
Filters