6.5

CVSS3.1

CVE-2026-20164 - Sensitive Information Disclosure through Improper Access Control in Splunk Enterprise

In Splunk Enterprise versions below 10.2.0, 10.0.3, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.11, and 9.3.2411.123, a low-privileged user that does not hold the "admin" or "power" Splunk roles could access the `/splunkd/__raw/servicesNS/-/-/con…

πŸ“… Published: March 11, 2026, 4:18 p.m. πŸ”„ Last Modified: March 25, 2026, 11:50 a.m.

6.3

CVSS3.1

CVE-2026-20165 - Sensitive Information Disclosure in MongoClient logging channel in Splunk Enterprise

In Splunk Enterprise versions below 10.2.1, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.7, 10.1.2507.17, 10.0.2503.12, and 9.3.2411.124, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve sensitive information by inspecting …

πŸ“… Published: March 11, 2026, 4:17 p.m. πŸ”„ Last Modified: March 25, 2026, 11:50 a.m.

2.1

CVSS4.0

CVE-2026-1524 - Auth misconfiguration when multiple providers enabled

An edgecase in SSO implementation in Neo4j Enterprise edition versions prior to version 2026.02 can lead to unauthorised access under the following conditions: If a neo4j admin configures two or more OIDC providers AND configures one or more of them to be an authorization provider AND configures …

πŸ“… Published: March 11, 2026, 4:16 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

4.3

CVSS3.1

CVE-2025-12555 - Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that, under certain conditions, could have allowed an authenticated user to access previous pipeline job information on projects with repository and CI/CD disabl…

πŸ“… Published: March 11, 2026, 4:07 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2026-30235 - Business Logic Error on OpenProject through hyperlinks in markdown using DOM clobbering

OpenProject is an open-source, web-based project management software. Prior to 17.2.0, this vulnerability occurs due to improper validation of OpenProject’s Markdown rendering, specifically in the hyperlink handling. This allows an attacker to inject malicious hyperlink payloads that perform DOM cl…

πŸ“… Published: March 11, 2026, 4:06 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2025-12576 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of service due to improper handling of webhook response data.

πŸ“… Published: March 11, 2026, 4:06 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

2.2

CVSS3.1

CVE-2025-12697 - Improper Encoding or Escaping of Output in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

πŸ“… Published: March 11, 2026, 4:06 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

3.5

CVSS3.1

CVE-2025-12704 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization under certain condi…

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

6.5

CVSS3.1

CVE-2025-13690 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to improper input validation on webhook custom header names under certa…

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.

7.5

CVSS3.1

CVE-2025-13929 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.0 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service by issuing specially crafted requests to repository archive endpoints under certain …

πŸ“… Published: March 11, 2026, 4:05 p.m. πŸ”„ Last Modified: March 20, 2026, 3:30 p.m.
Total resulsts: 349182
Page 1180 of 34,919
Β« previous page Β» next page
Filters