381
|
- |
|
-
|
-
|
An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLa…
New
|
CWE-1023
|
CVE-2024-5528
|
2025-02-5 20:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
382
|
7.1 |
HIGH
Network
|
-
|
-
|
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo…
New
|
CWE-611
XXE
|
CVE-2024-49352
|
2025-02-5 20:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
383
|
- |
|
-
|
-
|
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project…
New
|
CWE-286
Incorrect User Management
|
CVE-2024-6356
|
2025-02-5 19:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
384
|
- |
|
-
|
-
|
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to…
New
|
CWE-862
Missing Authorization
|
CVE-2024-1539
|
2025-02-5 19:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
385
|
- |
|
-
|
-
|
A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike th…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2023-6386
|
2025-02-5 19:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
386
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: don't skip expired elements during walk
There is an asymmetry between commit/abort and preparation phase if…
New
|
-
|
CVE-2023-52924
|
2025-02-5 19:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
387
|
5.3 |
MEDIUM
Network
-
|
-
|
The WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.0.8 vi…
New
|
CWE-200
Information Exposure
|
CVE-2024-13829
|
2025-02-5 15:15 |
2025-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
388
|
- |
|
-
|
-
|
This vulnerability allows appliance compromise at boot time.
Update
|
-
|
CVE-2025-24507
|
2025-02-5 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
389
|
- |
|
-
|
-
|
A specific authentication strategy allows to learn ids of PAM users associated with certain authentication types.
Update
|
-
|
CVE-2025-24506
|
2025-02-5 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
390
|
- |
|
-
|
-
|
This vulnerability allows a high-privileged authenticated PAM user to achieve remote command execution on the affected PAM system by uploading a specially crafted upgrade file.
Update
|
-
|
CVE-2025-24505
|
2025-02-5 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|