[NEW] [high] GitLab: Multiple vulnerabilities
A remote, authenticated attacker can exploit multiple vulnerabilities in GitLab to execute arbitrary code, perform Cross-Site Scripting, manipulate data, or disclose confidential information.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A remote, authenticated attacker can exploit multiple vulnerabilities in GitLab to execute arbitrary code, perform Cross-Site Scripting, manipulate data, or disclose confidential information.
An attacker can exploit multiple vulnerabilities in LiteLLM to disclose information, manipulate data, execute code, and bypass security measures.
An attacker can exploit multiple vulnerabilities in Progress Software MOVEit to bypass security measures, perform a Denial of Service attack, and conduct a Cross-Site Scripting attack.
An attacker can exploit multiple vulnerabilities in IBM Operational Decision Manager to execute arbitrary program code, escalate privileges, perform a Denial of Service attack, disclose information, manipulate files, and bypass security measures.
A remote, authenticated attacker can exploit multiple vulnerabilities in MISP to bypass security measures.
An attacker can exploit multiple vulnerabilities in MailPit to perform a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in OpenCTI to perform a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in RabbitMQ to disclose information.
A remote, authenticated attacker can exploit a vulnerability in Wazuh to conduct a denial of service attack.
A remote, authenticated attacker can exploit a vulnerability in Bitwarden to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Podman to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in CoreDNS to conduct a denial of service attack.
A local attacker can exploit a vulnerability in Perl to execute arbitrary program code and disclose information.
A remote, anonymous attacker can exploit a vulnerability in Gitea to bypass security measures.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct an unspecified attack.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or an unspecified attack.
A remote authenticated attacker can exploit multiple vulnerabilities in PostgreSQL to execute arbitrary code or bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in GStreamer to manipulate files and create a denial of service condition.
A local attacker can exploit multiple vulnerabilities in QEMU to disclose information.
A local attacker can exploit multiple vulnerabilities in QEMU and libvirt to disclose information and bypass security mechanisms.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in CoreDNS to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Ansible Automation Platform to conduct a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in Keycloak to manipulate files.
An attacker can exploit multiple vulnerabilities in Keycloak to escalate privileges, disclose information, bypass security measures, and conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in OpenVPN to manipulate data.
An attacker can exploit multiple vulnerabilities in CoreDNS to bypass security measures and conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Microsoft Windows products to execute arbitrary code, escalate privileges, conduct a Denial of Service attack, disclose information, and bypass security measures.
An attacker can exploit multiple vulnerabilities in Snipe-IT to disclose information, escalate privileges, and manipulate data.
An attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, perform SQL injection and cross-site scripting attacks, manipulate data, cause a Denial of Service condition, or disclose sensitive information, which may allow further at…
A local attacker can exploit a vulnerability in sudo to elevate their privileges.
Jakub Ciolek and Nicola Murino discovered that Go Cryptography incorrectly handled SSH agent responses. An attacker could use this to cause a denial of service. (CVE-2025-47913) Yuichi Watanabe discovered that Go Cryptography incorrectly handled SSH key exchanges. An attacker cou…
A remote, authenticated attacker can exploit multiple vulnerabilities in Snipe-IT to gain administrative privileges, bypass security measures, and manipulate data.
A remote, anonymous attacker can exploit a vulnerability in Microsoft Dynamics 365 to conduct a Cross-Site Scripting attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Foxit PDF Editor and Foxit PDF Reader to escalate privileges, cause a denial of service, execute code, and disclose information.
An attacker can exploit multiple vulnerabilities in Dell PowerProtect Data Domain to elevate their privileges to execute arbitrary program code, bypass security measures, conduct a Denial of Service attack, perform a Cross-Site Scripting attack, disclose information, and manipula…
A remote, authenticated attacker can exploit a vulnerability in OpenCTI to bypass security measures.
An attacker can exploit multiple vulnerabilities in Keycloak to present false information, disclose information, conduct a Cross-Site Scripting attack, bypass security precautions, and manipulate files.
A remote, anonymous attacker can exploit multiple vulnerabilities in Fluentd to execute arbitrary code, disclose information, or cause a Denial of Service.
An attacker can exploit multiple vulnerabilities in Microsoft Edge to gain elevated privileges, execute arbitrary code, bypass security measures, conduct spoofing and cross-site scripting attacks, disclose sensitive information, or trigger a denial-of-service condition.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - x86 architecture; - Block layer…
A remote, anonymous or authenticated attacker can exploit multiple vulnerabilities in Joomla to present false information, launch a Cross-Site Scripting attack, and modify data.
A remote, authenticated attacker can exploit multiple vulnerabilities in Joomla to conduct attacks such as Cross-Site Scripting (XSS), SQL injection, privilege escalation, authentication bypass, path traversal, local file inclusion (LFI), and unauthorized access.
Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability.
A vulnerability has been discovered in Microsoft Edge. It allows an attacker to cause a security policy bypass.
Multiple vulnerabilities have been discovered in Palo Alto Networks products. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and a remote denial of service.