Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2021-39893
A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without authorisation.
GitLab
14.1.7 / 14.2.5+
MEDIUM 6.5
CVE-2021-39869
In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
GitLab
14.1.7 / 14.2.5+
MEDIUM 6.5
CVE-2021-39872
In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired password to still access GitLa…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.4
CVE-2021-39878
A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowed an attacker to execute arbi…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.4
CVE-2021-39894
In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be used by attackers to exploit…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.3
CVE-2021-39875
In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or public project by visiting an AP…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.3
CVE-2021-39882
In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information about any GitLab user.
GitLab
14.1.7 / 14.2.5+
HIGH 8.1
CVE-2021-39867
In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by an attacker to trigger Server…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.4
CVE-2021-39866
A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project access tokens.
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.4
CVE-2021-39887
A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowed an attacker to execute arbi…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.5
CVE-2021-39877
A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a special…
GitLab
14.1.7 / 14.2.5+
MEDIUM 5.4
CVE-2021-39885
A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.…
GitLab
14.1.7 / 14.2.5+
MEDIUM 6.5
CVE-2021-22259
A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in dependencies API.
GitLab
14.1.7+
MEDIUM 6.5
CVE-2021-22244
Improper authorization in the vulnerability report feature in GitLab EE affecting all versions since 13.1 allowed a reporter to access vulnerability …
GitLab
13.12.9 / 14.0.7+
MEDIUM 5.4
CVE-2021-22250
Improper authorization in GitLab CE/EE affecting all versions since 13.3 allowed users to view and delete impersonation tokens that administrators cr…
GitLab
13.12.9 / 14.0.7+
MEDIUM 5.4
CVE-2021-22256
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
GitLab
13.12.9 / 14.0.7+
HIGH 8.8
CVE-2021-22236
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application. This vulnerability i…
GitLab
14.1.2+
MEDIUM 5.4
CVE-2021-22242EPSS 64%
Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting v…
GitLab
13.12.9 / 14.0.7+
MEDIUM 6.5
CVE-2021-22252
A confusion between tag and branch names in GitLab CE/EE affecting all versions since 13.7 allowed a Developer to access protected CI variables which…
GitLab
13.12.9 / 14.0.7+
MEDIUM 5.4
CVE-2021-22253
Improper authorization in GitLab EE affecting all versions since 13.4 allowed a user who previously had the necessary access to trigger deployments t…
GitLab
13.12.9 / 14.0.7+
MEDIUM 5.3
CVE-2021-22248
Improper authorization on the pipelines page in GitLab CE/EE affecting all versions since 13.12 allowed unauthorized users to view some pipeline info…
GitLab
13.12.9 / 14.0.7+
MEDIUM 6.5
CVE-2021-22246
A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of servic…
GitLab
13.11.6 / 13.12.6+
MEDIUM 5.4
CVE-2021-22238EPSS 72%
An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature i…
GitLab
13.12.9 / 14.0.7+
MEDIUM 6.4
CVE-2021-22234
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12…
GitLab
after 14.0.4
MEDIUM 5.4
CVE-2021-22241
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via …
GitLab
14.0.7 / 14.1.2+
MEDIUM 6.5
CVE-2021-22224
A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacke…
GitLab
13.12.6 / 14.0.2+
MEDIUM 5.4
CVE-2021-22225
Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-site scripting vulnerability …
GitLab
13.11.6 / 13.12.6+
HIGH 7.2
CVE-2021-22230
Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability affects GitLab CE/EE 9.3 and l…
GitLab
13.11.6 / 13.12.6+
MEDIUM 6.1
CVE-2021-22227
A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to send a malicious link to a v…
GitLab
13.11.6 / 13.12.6+
MEDIUM 6.5
CVE-2021-22228
An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13.12.6, and all versions start…
GitLab
13.11.6 / 13.12.6+