4.3

CVSS3.1

CVE-2025-49192 - Clickjacking

The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of tโ€ฆ

๐Ÿ“… Published: June 12, 2025, 2:12 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:30 p.m.

4.8

CVSS3.1

CVE-2025-49191 - Dashboards and iFrames can link malicious web content

Linked URLs during the creation of iFrame widgets and dashboards are vulnerable to code execution. The URLs get embedded as iFrame widgets, making it possible to attack other users that access the dashboard by including malicious code. The attack is only possible if the attacker is authorized to crโ€ฆ

๐Ÿ“… Published: June 12, 2025, 2:08 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:31 p.m.

4.3

CVSS3.1

CVE-2025-49190 - Server-Side Request Forgery

The application is vulnerable to Server-Side Request Forgery (SSRF). An endpoint can be used to send server internal requests to other ports.

๐Ÿ“… Published: June 12, 2025, 2:06 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:33 p.m.

5.3

CVSS3.1

CVE-2025-49189 - Cookie missing HttpOnly flag

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies.

๐Ÿ“… Published: June 12, 2025, 2:03 p.m. ๐Ÿ”„ Last Modified: Feb. 6, 2026, 2:29 p.m.

5.3

CVSS3.1

CVE-2024-9512 - Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

๐Ÿ“… Published: June 12, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: Aug. 8, 2025, 6:22 p.m.

5.3

CVSS3.1

CVE-2025-49188 - Sensitive Data in URL

The application sends user credentials as URL parameters instead of POST bodies, making it vulnerable to information gathering.

๐Ÿ“… Published: June 12, 2025, 2:02 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:32 p.m.

5.3

CVSS3.1

CVE-2025-49187 - User enumeration

For failed login attempts, the application returns different error messages depending on whether the login failed due to an incorrect password or a non-existing username. This allows an attacker to guess usernames until they find an existing one.

๐Ÿ“… Published: June 12, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:33 p.m.

5.3

CVSS3.1

CVE-2025-49186 - No brute-force protection

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks.

๐Ÿ“… Published: June 12, 2025, 1:27 p.m. ๐Ÿ”„ Last Modified: Feb. 3, 2026, 2:39 p.m.

5.5

CVSS3.1

CVE-2025-49185 - Stored Cross-Site-Script

The web application is susceptible to cross-site-scripting attacks. An attacker who can create new dashboard widgets can inject malicious JavaScript code into the Transform Function which will be executed when the widget receives data from its data source.

๐Ÿ“… Published: June 12, 2025, 1:25 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:33 p.m.

7.5

CVSS3.1

CVE-2025-49184 - Information disclosure to unauthorized user

A remote unauthorized attacker may gather sensitive information of the application, due to missing authorization of configuration settings of the product.

๐Ÿ“… Published: June 12, 2025, 1:24 p.m. ๐Ÿ”„ Last Modified: Jan. 29, 2026, 5:58 p.m.
Total resulsts: 349182
Page 5044 of 34,919
ยซ previous page ยป next page
Filters