2.7

CVSS3.1

CVE-2025-4972 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privileges to bypass group-level user invitation restrictions by manipulating group invitation functionality.

πŸ“… Published: July 10, 2025, 8:30 a.m. πŸ”„ Last Modified: July 25, 2025, 4:40 p.m.

2.7

CVSS3.1

CVE-2025-6168 - Incorrect Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.

πŸ“… Published: July 10, 2025, 8:30 a.m. πŸ”„ Last Modified: July 25, 2025, 4:41 p.m.

8.7

CVSS3.1

CVE-2025-6948 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

πŸ“… Published: July 10, 2025, 8:30 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 5:50 p.m.

6.5

CVSS3.1

CVE-2025-6395 - Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()

A NULL pointer dereference flaw was found in the GnuTLS software in _gnutls_figure_common_ciphersuite().

πŸ“… Published: July 10, 2025, 7:56 a.m. πŸ”„ Last Modified: April 23, 2026, 6:16 p.m.

6.5

CVSS3.1

CVE-2025-32988 - Gnutls: vulnerability in gnutls othername san export

A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node i…

πŸ“… Published: July 10, 2025, 7:55 a.m. πŸ”„ Last Modified: April 20, 2026, 10:16 p.m.

5.3

CVSS3.1

CVE-2025-32989 - Gnutls: vulnerability in gnutls sct extension parsing

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1…

πŸ“… Published: July 10, 2025, 7:54 a.m. πŸ”„ Last Modified: April 20, 2026, 10:16 p.m.

4.8

CVSS3.1

CVE-2025-6236 - Hostel < 1.1.5.9 - Admin+ Stored XSS

The Hostel WordPress plugin before 1.1.5.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

πŸ“… Published: July 10, 2025, 6 a.m. πŸ”„ Last Modified: July 11, 2025, 6:28 p.m.

6.1

CVSS3.1

CVE-2025-6234 - Hostel < 1.1.5.8 - Reflected XSS

The Hostel WordPress plugin before 1.1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

πŸ“… Published: July 10, 2025, 6 a.m. πŸ”„ Last Modified: July 11, 2025, 6:29 p.m.

5.5

CVSS3.1

CVE-2025-7387 - Lana Downloads Manager <= 1.10.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Lana Downloads Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the endpoint parameters in versions up to, and including, 1.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacker…

πŸ“… Published: July 10, 2025, 5:24 a.m. πŸ”„ Last Modified: April 20, 2026, 8:30 p.m.

5.6

CVSS3.1

CVE-2025-46406 -

A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high level access in one Division to perform limited privileged activities across the Division boundary. This issue affects Command Centre Server: 9.30 prior to 9.30.1874Β (MR1), 9.20…

πŸ“… Published: July 10, 2025, 3:10 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 4690 of 34,919
Β« previous page Β» next page
Filters