6.5

CVSS3.1

CVE-2024-3976 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unaut…

📅 Published: Feb. 5, 2025, 12:02 p.m. 🔄 Last Modified: Aug. 6, 2025, 6:59 p.m.

4.3

CVSS3.1

CVE-2024-49348 - IBM Cloud Pak for Business Automation incorrect privilege assignment

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly g…

📅 Published: Feb. 5, 2025, 11:30 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:36 p.m.

6.4

CVSS3.1

CVE-2024-52365 - IBM Cloud Pak for Business Automation cross-site scripting

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thu…

📅 Published: Feb. 5, 2025, 11:28 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:28 p.m.

5.4

CVSS3.1

CVE-2024-52364 - IBM Cloud Pak for Business Automation cross-site scripting

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus alter…

📅 Published: Feb. 5, 2025, 11:22 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:30 p.m.

7.1

CVSS3.1

CVE-2024-49352 - IBM Cognos Anaytics XML external entity injection

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resou…

📅 Published: Feb. 5, 2025, 10:58 a.m. 🔄 Last Modified: July 2, 2025, 3:59 p.m.

3.5

CVSS3.1

CVE-2024-5528 - Incomplete Comparison with Missing Factors in GitLab

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

📅 Published: Feb. 5, 2025, 10:31 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:51 p.m.

7.5

CVSS3.1

CVE-2024-9631 - Inefficient Algorithmic Complexity in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

📅 Published: Feb. 5, 2025, 10:30 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:54 p.m.

4.4

CVSS3.1

CVE-2024-6356 - Incorrect User Management in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

📅 Published: Feb. 5, 2025, 10:02 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:51 p.m.

4.3

CVSS3.1

CVE-2024-1539 - Missing Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.

📅 Published: Feb. 5, 2025, 9:46 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:51 p.m.

6.5

CVSS3.1

CVE-2023-6386 - Allocation of Resources Without Limits or Throttling in GitLab

A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.

📅 Published: Feb. 5, 2025, 9:31 a.m. 🔄 Last Modified: Aug. 5, 2025, 9:03 p.m.
Total resulsts: 349182
Page 6842 of 34,919
« previous page » next page
Filters