7.5

CVSS3.1

CVE-2025-49183 - Unencrypted communication (HTTP)

All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files.

πŸ“… Published: June 12, 2025, 1:21 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:59 p.m.

7.5

CVSS3.1

CVE-2025-49182 - Credential disclosure

Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application.

πŸ“… Published: June 12, 2025, 1:15 p.m. πŸ”„ Last Modified: Jan. 29, 2026, 5:59 p.m.

8.6

CVSS3.1

CVE-2025-49181 - Configurations endpoint does not require authorization

Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack.

πŸ“… Published: June 12, 2025, 1:14 p.m. πŸ”„ Last Modified: Feb. 3, 2026, 2:35 p.m.

7.5

CVSS3.1

CVE-2025-0673 - Loop with Unreachable Exit Condition ('Infinite Loop') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinite redirect loop, potentially leading to a denial of service condition.

πŸ“… Published: June 12, 2025, 11:03 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:21 p.m.

4.3

CVSS3.1

CVE-2025-5195 - Authorization Bypass Through User-Controlled Key in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure.

πŸ“… Published: June 12, 2025, 10:31 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:21 p.m.

6.5

CVSS3.1

CVE-2025-1478 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Names could be used to trigger a denial of service.

πŸ“… Published: June 12, 2025, 10:02 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:30 p.m.

6.5

CVSS3.1

CVE-2025-1516 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Names could be used to trigger a denial of service.

πŸ“… Published: June 12, 2025, 10:02 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:30 p.m.

8.7

CVSS3.1

CVE-2025-2254 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper viewer functionality lead to Cross-Site scripting attacks.

πŸ“… Published: June 12, 2025, 10:02 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:31 p.m.

8.7

CVSS3.1

CVE-2025-4278 - Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

πŸ“… Published: June 12, 2025, 10:02 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:23 p.m.

6.5

CVSS3.1

CVE-2025-5996 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP responses could allow an authenticated user to cause denial of service.

πŸ“… Published: June 12, 2025, 10:02 a.m. πŸ”„ Last Modified: Aug. 8, 2025, 6:20 p.m.
Total resulsts: 349182
Page 5045 of 34,919
Β« previous page Β» next page
Filters