gitlab
1,383 tracked vulnerabilities.
CVE-2020-13341
MEDIUM
GitLab <13.2.10-13.4.2 - Privilege Escalation
Oct 12, 2020
CVSS 4.9
EPSS 0.00
CVE-2020-13344
MEDIUM
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 08, 2020
CVSS 5.7
EPSS 0.00
CVE-2020-13340
HIGH
GitLab < 13.2.10, 13.3.7, 13.4.2 - Stored Cross-Site Scripting in CI Job Log
Oct 08, 2020
CVSS 8.7
EPSS 0.02
CVE-2020-13339
MEDIUM
GitLab < 13.2.10 - Stored Cross-Site Scripting in SVG File Preview
Oct 08, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-13342
LOW
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 07, 2020
CVSS 2.7
EPSS 0.00
CVE-2020-13347
CRITICAL
Gitlab Runner <13.2.4-13.4.1 - Command Injection
Oct 07, 2020
CVSS 9.1
EPSS 0.01
CVE-2020-13346
MEDIUM
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 07, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-13335
MEDIUM
GitLab >=7.12 - Privilege Escalation
Oct 07, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-13334
MEDIUM
GitLab <13.2.10-13.4.2 - Info Disclosure
Oct 07, 2020
CVSS 5.9
EPSS 0.00
CVE-2020-13345
MEDIUM
GitLab 10.8.0-13.2.9 - Reflected Cross-Site Scripting on Multiple Routes
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-13343
HIGH
GitLab 11.2.0-13.4.2 - Unauthorized Custom Project Template Exposure
Oct 06, 2020
CVSS 7.5
EPSS 0.00
CVE-2020-13333
MEDIUM
GitLab 13.1-13.3 - Denial of Service via Release Asset Link Update API
Oct 06, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-13338
MEDIUM
GitLab <12.10.13, 13.0.8, 13.1.2 - XSS
Oct 02, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-13337
HIGH
GitLab 12.10-12.10.12 - Stored Cross-Site Scripting via Group Name
Oct 02, 2020
CVSS 7.2
EPSS 0.00
CVE-2020-13336
MEDIUM
GitLab 11.8-12.10.12 - Stored Cross-Site Scripting in Error Tracking Feature
Sep 30, 2020
CVSS 4.0
EPSS 0.00
CVE-2020-13331
MEDIUM
GitLab < 12.10.13 - Stored Cross-Site Scripting in Wiki Pages
Sep 30, 2020
CVSS 5.4
EPSS 0.00
CVE-2020-13330
MEDIUM
GitLab < 12.10.13 - Stored Cross-Site Scripting in Bitbucket Project Import
Sep 30, 2020
CVSS 4.4
EPSS 0.00
CVE-2020-13329
MEDIUM
GitLab 12.6.2-12.10.13 - Stored Cross-Site Scripting in Blob View
Sep 30, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-13328
MEDIUM
GitLab 12.0.0-12.10.13 - Stored Cross-Site Scripting via PyPi Files API
Sep 30, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-13326
MEDIUM
GitLab 11.8.0-12.10.12 - GitHub Project Import Restriction Bypass
Sep 30, 2020
CVSS 4.3
EPSS 0.00
CVE-2020-13325
HIGH
GitLab 12.9.0-12.10.13 - Denial of Service via Issue Comment Section
Sep 30, 2020
CVSS 7.1
EPSS 0.00
CVE-2020-13324
MEDIUM
GitLab 9.4.0-12.10.13 - Unprotected User Data Exposure via API
Sep 30, 2020
CVSS 6.5
EPSS 0.00
CVE-2020-13323
HIGH
GitLab 8.5.0-12.10.13 - Unauthenticated Private Merge Request Exposure via Todos
Sep 30, 2020
CVSS 7.7
EPSS 0.00
CVE-2020-13322
HIGH
GitLab >12.9 - Privilege Escalation
Sep 30, 2020
CVSS 7.2
EPSS 0.00
CVE-2020-13321
HIGH
GitLab < 12.10.13 - Username Format Restriction Bypass
Sep 30, 2020
CVSS 8.3
EPSS 0.00