7.5

CVSS3.1

CVE-2024-2878 - Allocation of Resources Without Limits or Throttling in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.

📅 Published: Feb. 5, 2025, 12:21 p.m. 🔄 Last Modified: Aug. 6, 2025, 8:17 p.m.

6.5

CVSS3.1

CVE-2024-3976 - Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unaut…

📅 Published: Feb. 5, 2025, 12:02 p.m. 🔄 Last Modified: Aug. 6, 2025, 6:59 p.m.

4.3

CVSS3.1

CVE-2024-49348 - IBM Cloud Pak for Business Automation incorrect privilege assignment

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 allows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly g…

📅 Published: Feb. 5, 2025, 11:30 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:36 p.m.

6.4

CVSS3.1

CVE-2024-52365 - IBM Cloud Pak for Business Automation cross-site scripting

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thu…

📅 Published: Feb. 5, 2025, 11:28 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:28 p.m.

5.4

CVSS3.1

CVE-2024-52364 - IBM Cloud Pak for Business Automation cross-site scripting

IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus alter…

📅 Published: Feb. 5, 2025, 11:22 a.m. 🔄 Last Modified: Aug. 12, 2025, 4:30 p.m.

7.1

CVSS3.1

CVE-2024-49352 - IBM Cognos Anaytics XML external entity injection

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resou…

📅 Published: Feb. 5, 2025, 10:58 a.m. 🔄 Last Modified: July 2, 2025, 3:59 p.m.

3.5

CVSS3.1

CVE-2024-5528 - Incomplete Comparison with Missing Factors in GitLab

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

📅 Published: Feb. 5, 2025, 10:31 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:51 p.m.

7.5

CVSS3.1

CVE-2024-9631 - Inefficient Algorithmic Complexity in GitLab

An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.

📅 Published: Feb. 5, 2025, 10:30 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:54 p.m.

4.4

CVSS3.1

CVE-2024-6356 - Incorrect User Management in GitLab

An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.

📅 Published: Feb. 5, 2025, 10:02 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:51 p.m.

4.3

CVSS3.1

CVE-2024-1539 - Missing Authorization in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.

📅 Published: Feb. 5, 2025, 9:46 a.m. 🔄 Last Modified: Aug. 6, 2025, 6:51 p.m.
Total resulsts: 343942
Page 6318 of 34,395
« previous page » next page
Filters