gitlab
1,383 tracked vulnerabilities.
CVE-2019-6793
HIGH
NUCLEI
GitLab 10.0.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Unauthenticated Server-Side Request Forgery via Jira Integration
Sep 09, 2019
CVSS 7.0
EPSS 0.05
CVE-2019-6792
MEDIUM
GitLab 8.9.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Path Disclosure via Project Import Error Message
Sep 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-6789
MEDIUM
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Information Disclosure via Project Move Notification
Sep 09, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-6788
HIGH
GitLab 8.4.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Information Disclosure via OAuth Token Covert Redirect
Sep 09, 2019
CVSS 7.5
EPSS 0.20
CVE-2019-6786
MEDIUM
GitLab <11.5.8-11.7.1 - Info Disclosure
Sep 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6785
MEDIUM
GitLab 7.4.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Denial of Service via Markdown Field Input
Sep 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-6784
MEDIUM
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Stored Cross-Site Scripting via KaTeX Markdown Processing
Sep 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-6783
HIGH
GitLab < 11.5.8, 11.6.x < 11.6.6, 11.7.x < 11.7.1 - Path Traversal and Remote Code Execution via GitLab Pages
Sep 09, 2019
CVSS 8.8
EPSS 0.02
CVE-2019-6782
HIGH
GitLab 11.3.0-11.5.7, 11.6.0-11.6.5, 11.7.0 - Information Disclosure via Private Profile Contribution Data
Sep 09, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-11605
HIGH
GitLab <11.8.10-11.10.3 - Info Disclosure
Sep 09, 2019
CVSS 7.5
EPSS 0.00
CVE-2019-11549
MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-11548
MEDIUM
GitLab 5.4.0-11.8.9 - Unauthenticated Incorrect Access Control in Note Endpoint
Sep 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-11547
MEDIUM
GitLab < 11.8.9, 11.9.x < 11.9.10, 11.10.x < 11.10.2 - Cross-Site Scripting via Merge Request Notification Email
Sep 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-11546
MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-11545
MEDIUM
GitLab CE <11.9.10, <11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-11544
MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
Sep 09, 2019
CVSS 4.3
EPSS 0.00
CVE-2019-5473
HIGH
GitLab - Authentication Bypass via Email Verification
Sep 09, 2019
CVSS 7.2
EPSS 0.00
CVE-2019-5471
MEDIUM
GitLab 11.11.0-11.11.6 - Stored Cross-Site Scripting in Email Notification Feature
Sep 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-5467
MEDIUM
GitLab 11.11.2-11.11.6 - Stored Cross-Site Scripting in Wiki Pages
Sep 09, 2019
CVSS 5.4
EPSS 0.00
CVE-2019-5463
MEDIUM
GitLab 11.11.0-11.11.6 - Missing Authorization in CI Badge Images Endpoint
Sep 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2019-5461
LOW
GitLab 11.11.0-11.11.6 - Server-Side Request Forgery via GitHub Integration
Sep 09, 2019
CVSS 3.5
EPSS 0.00
CVE-2019-14943
CRITICAL
GitLab 12.0-12.1.4 - Use of Hard-coded Credentials
Aug 29, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-9866
MEDIUM
GitLab <11.7.7, <11.8.3 - Info Disclosure
May 29, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-9732
CRITICAL
GitLab <11.6.10-11.8.1 - Incorrect Access Control
May 29, 2019
CVSS 9.8
EPSS 0.00
CVE-2019-9485
CRITICAL
GitLab <11.6.10-11.8.1 - Info Disclosure
May 29, 2019
CVSS 9.8
EPSS 0.00