6.5

CVSS3.1

CVE-2025-3111 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 10.2 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in the Kubernetes integration could allow an authenticated user to cause denial of service..

📅 Published: May 22, 2025, 1:30 p.m. 🔄 Last Modified: May 29, 2025, 3:58 p.m.

4.9

CVSS3.1

CVE-2025-4979 - Insufficient Granularity of Access Control in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. An attacker may be able to reveal masked or hidden CI variables (that they did not author) in the WebUI, by simply creating their own variable and observing the HTTP res…

📅 Published: May 22, 2025, 1:30 p.m. 🔄 Last Modified: Aug. 8, 2025, 6:33 p.m.

7.2

CVSS3.1

CVE-2025-3945 - Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’)

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Ent…

📅 Published: May 22, 2025, 12:47 p.m. 🔄 Last Modified: June 5, 2025, 2:19 p.m.

7.2

CVSS3.1

CVE-2025-3944 - Incorrect Permission Assignment for Critical Resource

Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.…

📅 Published: May 22, 2025, 12:44 p.m. 🔄 Last Modified: June 4, 2025, 7:27 p.m.

4.1

CVSS3.1

CVE-2025-3943 - Use of GET Request Method With sensitive Query Strings

Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagar…

📅 Published: May 22, 2025, 12:42 p.m. 🔄 Last Modified: June 4, 2025, 7:27 p.m.

4.3

CVSS3.1

CVE-2025-3942 - Improper Output Neutralization for Logs

Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterpris…

📅 Published: May 22, 2025, 12:40 p.m. 🔄 Last Modified: June 4, 2025, 7:27 p.m.

5.4

CVSS3.1

CVE-2025-3941 - Improper Handling of Windows: DATA Alternate Data Stream

Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Secu…

📅 Published: May 22, 2025, 12:38 p.m. 🔄 Last Modified: June 4, 2025, 7:28 p.m.

5.3

CVSS3.1

CVE-2025-3940 - Improper Use of Validation Framework

Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise S…

📅 Published: May 22, 2025, 12:35 p.m. 🔄 Last Modified: June 4, 2025, 7:28 p.m.

5.3

CVSS3.1

CVE-2025-3939 - Observable Response Discrepancy

Observable Response Discrepancy vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before…

📅 Published: May 22, 2025, 12:33 p.m. 🔄 Last Modified: June 4, 2025, 7:29 p.m.

6.8

CVSS3.1

CVE-2025-3938 - Missing Cryptographic Step

Missing Cryptographic Step vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Cryptanalysis. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14…

📅 Published: May 22, 2025, 12:32 p.m. 🔄 Last Modified: June 4, 2025, 7:29 p.m.
Total resulsts: 349182
Page 5289 of 34,919
« previous page » next page
Filters