Show filters
1,948 Total Results
Displaying 31-40 of 1,948
Sort by:
Attacker Value
Unknown
CVE-2025-0376
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.
0
Attacker Value
Unknown
CVE-2024-12379
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.
0
Attacker Value
Unknown
CVE-2024-10383
Disclosure Date: February 07, 2025 (last updated February 08, 2025)
An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE
0
Attacker Value
Unknown
CVE-2025-25168
Disclosure Date: February 07, 2025 (last updated February 12, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in blackandwhitedigital BookPress – For Book Authors allows Cross-Site Scripting (XSS). This issue affects BookPress – For Book Authors: from n/a through 1.2.7.
0
Attacker Value
Unknown
CVE-2025-25167
Disclosure Date: February 07, 2025 (last updated February 12, 2025)
Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects BookPress – For Book Authors: from n/a through 1.2.7.
0
Attacker Value
Unknown
CVE-2025-1072
Disclosure Date: February 07, 2025 (last updated February 07, 2025)
A Denial of Service (DoS) issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2. A denial of service could occur upon importing maliciously crafted content using the Fogbugz importer.
0
Attacker Value
Unknown
CVE-2024-2878
Disclosure Date: February 05, 2025 (last updated February 06, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.7 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible for an attacker to cause a denial of service by crafting unusual search terms for branch names.
0
Attacker Value
Unknown
CVE-2024-3976
Disclosure Date: February 05, 2025 (last updated February 06, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.
0
Attacker Value
Unknown
CVE-2024-9631
Disclosure Date: February 05, 2025 (last updated February 05, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.
0
Attacker Value
Unknown
CVE-2024-5528
Disclosure Date: February 05, 2025 (last updated February 05, 2025)
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.
0