6.9

CVSS4.0

CVE-2025-13200 - SourceCodester Farm Management System exposure of information through directory listing

A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through directory listing. The attack is possible to be carried out remotely. The exploit has been publicly discl…

πŸ“… Published: Nov. 15, 2025, 3:32 p.m. πŸ”„ Last Modified: Nov. 19, 2025, 7:34 p.m.

4.8

CVSS4.0

CVE-2025-13199 - code-projects Email Logging Interface signup.cpp path traversal

A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been made public and coul…

πŸ“… Published: Nov. 15, 2025, 10:32 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 7:41 p.m.

5.1

CVSS4.0

CVE-2025-13198 - DouPHP file.class.php unrestricted upload

A vulnerability has been found in DouPHP up to 1.8 Release 20251022. This impacts an unknown function of the file upload/include/file.class.php. The manipulation of the argument File leads to unrestricted upload. Remote exploitation of the attack is possible. The exploit has been disclosed to the p…

πŸ“… Published: Nov. 15, 2025, 9:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2025-12983 - Memory Allocation with Excessive Size Value in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content with nested formatting …

πŸ“… Published: Nov. 15, 2025, 8:13 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 7:44 p.m.

4.3

CVSS3.1

CVE-2025-2615 - Insertion of Sensitive Information Into Sent Data in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

πŸ“… Published: Nov. 15, 2025, 8:04 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 5:46 p.m.

3.5

CVSS3.1

CVE-2025-6945 - Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.

πŸ“… Published: Nov. 15, 2025, 8:04 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 9:07 p.m.

5.3

CVSS3.1

CVE-2025-6171 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker with reporter access to view branch names and pipeline details by accessing the packages API endpoint even when…

πŸ“… Published: Nov. 15, 2025, 8:04 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 9:09 p.m.

4.3

CVSS3.1

CVE-2025-7000 - Insertion of Sensitive Information Into Sent Data in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.6 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that, under specific conditions, could have allowed unauthorized users to view confidential branch names by accessing project issues with related merge requests.

πŸ“… Published: Nov. 15, 2025, 8:04 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 9:03 p.m.

3.1

CVSS3.1

CVE-2025-7736 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to bypass access control restrictions and view GitLab Pages content intended only for project members by authen…

πŸ“… Published: Nov. 15, 2025, 8:04 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 7:46 p.m.

4.3

CVSS3.1

CVE-2025-11865 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions from 18.1 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that, under certain circumstances, could have allowed an attacker to remove Duo flows of another user.

πŸ“… Published: Nov. 15, 2025, 8:03 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 5:59 p.m.
Total resulsts: 349182
Page 3003 of 34,919
Β« previous page Β» next page
Filters