6.5

CVSS3.1

CVE-2026-2845 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.

πŸ“… Published: Feb. 25, 2026, 8:04 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

6.9

CVSS4.0

CVE-2026-3200 - z-9527 admin user.js getUsers sql injection

A vulnerability was identified in z-9527 admin 1.0/2.0. The affected element is the function checkName/register/login/getUser/getUsers of the file /server/controller/user.js. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might b…

πŸ“… Published: Feb. 25, 2026, 8:02 p.m. πŸ”„ Last Modified: April 18, 2026, 5:45 p.m.

5.5

CVSS4.0

CVE-2026-25942 - FreeRDP has global-buffer-overflow in xf_rail_server_execute_result

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_rail_server_execute_result` indexes the global `error_code_names[]` array (7 elements, indices 0–6) with an unchecked `execResult->execResult` value received from the server, allowing an out-of-bounds read…

πŸ“… Published: Feb. 25, 2026, 8:01 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

6.2

CVSS3.1

CVE-2026-22721 - VMware Aria Operations privilege escalation vulnerability

VMware Aria Operations contains a privilege escalation vulnerability. A malicious actor with privileges in vCenter to access Aria Operations may leverage this vulnerability to obtain administrative access in VMware Aria Operations. To remediate CVE-2026-22721, apply the patches listed in the 'Fixed…

πŸ“… Published: Feb. 25, 2026, 8 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

4.3

CVSS3.1

CVE-2026-25941 - FreeRDP: vuln_1_15_1 RDPGFX WIRE_TO_SURFACE_2 Out-of-Bounds Read

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory b…

πŸ“… Published: Feb. 25, 2026, 7:55 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

6.1

CVSS3.1

CVE-2026-25736 - Rucio WebUI has a Stored Cross-site Scripting (XSS) Vulnerability in its Custom RSE Attribute

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Custom RSE Attribute of the WebUI where …

πŸ“… Published: Feb. 25, 2026, 7:50 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

6.1

CVSS3.1

CVE-2026-25735 - Rucio WebUI has a Stored Cross-site Scripting (XSS) vulnerability its Identity Name

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Identity Name of the WebUI where attacke…

πŸ“… Published: Feb. 25, 2026, 7:43 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

6.5

CVSS3.1

CVE-2025-3525 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI trigge…

πŸ“… Published: Feb. 25, 2026, 7:33 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 4:17 p.m.

6.1

CVSS3.1

CVE-2026-25734 - Rucio WebUI has Stored Cross-site Scripting (XSS) in RSE Metadata

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the RSE metadata of the WebUI where attacker…

πŸ“… Published: Feb. 25, 2026, 7:33 p.m. πŸ”„ Last Modified: April 17, 2026, 3 p.m.

4.3

CVSS3.1

CVE-2025-14103 - Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.

πŸ“… Published: Feb. 25, 2026, 7:33 p.m. πŸ”„ Last Modified: Feb. 27, 2026, 4:18 p.m.
Total resulsts: 347827
Page 1302 of 34,783
Β« previous page Β» next page
Filters