gitlab

1,383 tracked vulnerabilities.

CVE-2020-13341 MEDIUM
GitLab <13.2.10-13.4.2 - Privilege Escalation
Oct 12, 2020
CVSS 4.9
EPSS 0.00
CVE-2020-13344 MEDIUM
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 08, 2020
CVSS 5.7
EPSS 0.00
CVE-2020-13340 HIGH
GitLab < 13.2.10, 13.3.7, 13.4.2 - Stored Cross-Site Scripting in CI Job Log
Oct 08, 2020
CVSS 8.7
EPSS 0.02
CVE-2020-13339 MEDIUM
GitLab < 13.2.10 - Stored Cross-Site Scripting in SVG File Preview
Oct 08, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-13342 LOW
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 07, 2020
CVSS 2.7
EPSS 0.00
CVE-2020-13347 CRITICAL
Gitlab Runner <13.2.4-13.4.1 - Command Injection
Oct 07, 2020
CVSS 9.1
EPSS 0.01
CVE-2020-13346 MEDIUM
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 07, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-13335 MEDIUM
GitLab >=7.12 - Privilege Escalation
Oct 07, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-13334 MEDIUM
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 07, 2020
CVSS 5.9
EPSS 0.00
CVE-2020-13345 MEDIUM
GitLab 10.8.0-13.2.9 - Reflected Cross-Site Scripting on Multiple Routes
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-13343 HIGH
GitLab 11.2.0-13.4.2 - Unauthorized Custom Project Template Exposure
Oct 06, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-13333 MEDIUM
GitLab 13.1-13.3 - Denial of Service via Release Asset Link Update API
Oct 06, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-13338 MEDIUM
GitLab <12.10.13, 13.0.8, 13.1.2 - XSS
Oct 02, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-13337 HIGH
GitLab 12.10-12.10.12 - Stored Cross-Site Scripting via Group Name
Oct 02, 2020
CVSS 7.2
EPSS 0.00
CVE-2020-13336 MEDIUM
GitLab 11.8-12.10.12 - Stored Cross-Site Scripting in Error Tracking Feature
Sep 30, 2020
CVSS 4.0
EPSS 0.00
CVE-2020-13331 MEDIUM
GitLab < 12.10.13 - Stored Cross-Site Scripting in Wiki Pages
Sep 30, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-13330 MEDIUM
GitLab < 12.10.13 - Stored Cross-Site Scripting in Bitbucket Project Import
Sep 30, 2020
CVSS 4.4
EPSS 0.00
CVE-2020-13329 MEDIUM
GitLab 12.6.2-12.10.13 - Stored Cross-Site Scripting in Blob View
Sep 30, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-13328 MEDIUM
GitLab 12.0.0-12.10.13 - Stored Cross-Site Scripting via PyPi Files API
Sep 30, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-13326 MEDIUM
GitLab 11.8.0-12.10.12 - GitHub Project Import Restriction Bypass
Sep 30, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-13325 HIGH
GitLab 12.9.0-12.10.13 - Denial of Service via Issue Comment Section
Sep 30, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-13324 MEDIUM
GitLab 9.4.0-12.10.13 - Unprotected User Data Exposure via API
Sep 30, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-13323 HIGH
GitLab 8.5.0-12.10.13 - Unauthenticated Private Merge Request Exposure via Todos
Sep 30, 2020
CVSS 7.7
EPSS 0.00
CVE-2020-13322 HIGH
GitLab >12.9 - Privilege Escalation
Sep 30, 2020
CVSS 7.2
EPSS 0.00
CVE-2020-13321 HIGH
GitLab < 12.10.13 - Username Format Restriction Bypass
Sep 30, 2020
CVSS 8.3
EPSS 0.00