Search CVE reports


Toggle filters

81 – 90 of 1413 results


CVE-2025-0811

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1. Improper rendering of certain file types leads to cross-site scripting.

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2024-9773

Medium priority
Ignored

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2025-30204

Medium priority
Needs evaluation

golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data)...

2 affected packages

golang-github-golang-jwt-jwt, golang-github-golang-jwt-jwt-v5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-golang-jwt-jwt Needs evaluation Needs evaluation Not in release
golang-github-golang-jwt-jwt-v5 Needs evaluation Not in release Not in release
Show less packages

CVE-2025-29923

Medium priority
Needs evaluation

go-redis is the official Redis client library for the Go programming language. Prior to 9.5.5, 9.6.3, and 9.7.3, go-redis potentially responds out of order when `CLIENT SETINFO` times out during connection establishment. This can...

1 affected package

golang-github-go-redis-redis

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-redis-redis Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-29786

Medium priority
Needs evaluation

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract...

1 affected package

golang-github-antonmedv-expr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-antonmedv-expr Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2025-0652

Medium priority
Ignored

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2024-13054

Medium priority
Ignored

An issue was discovered in GitLab CE/EE affecting all versions before 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2. where a denial of service vulnerability could allow an attacker to cause a system reboot under certain...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2024-12380

Medium priority
Ignored

An issue was discovered in GitLab EE/CE affecting all versions starting from 11.5 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. Certain user inputs in repository...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2025-1540

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as...

1 affected package

gitlab

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gitlab Not in release Not in release Not in release
Show less packages

CVE-2025-27144

Medium priority
Needs evaluation

Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions...

1 affected package

golang-github-go-jose-go-jose

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-go-jose-go-jose Needs evaluation Not in release Not in release
Show less packages