Total CVEs

111,140

Critical Severity

796

High Severity

2,523

Last 7 Days

1,237
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 21 - 32 of 32 CVEs
CVE-2025-13927 HIGH - 7.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.9 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted requests with malformed authentication data.

Vendor: GitLab
Product: GitLab
Published: Jan 22, 2026
Source: NVD
CVE-2025-13335 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that under certain circumstances could have allowed an authenticated user to create a denial of service condition by configuring malformed Wiki documents that byp...

Vendor: GitLab
Product: GitLab
Published: Jan 22, 2026
Source: NVD
CVE-2025-11224 MEDIUM - 5.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality.

Vendor: gitlab
Product: gitlab
Published: Jan 14, 2026
Source: NVD
CVE-2026-0830 HIGH - 7.8

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.

Published: Jan 09, 2026
Source: NVD
CVE-2025-9222 MEDIUM - 5.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-3950 LOW - 3.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-13781 MEDIUM - 6.5

GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-13772 MEDIUM - 4.3

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace identifiers in API reque...

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-13761 CRITICAL - 9.6

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to visit a special...

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-11246 MEDIUM - 5.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrelated projects by manipulating GraphQL runner assoc...

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-10569 MEDIUM - 6.5

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted responses to external API calls.

Vendor: gitlab
Product: gitlab
Published: Jan 09, 2026
Source: NVD
CVE-2025-61916 HIGH - 7.9

Spinnaker is an open source, multi-cloud continuous delivery platform. Versions prior to 2025.1.6, 2025.2.3, and 2025.3.0 are vulnerable to server-side request forgery. The primary impact is allowing users to fetch data from a remote URL. This data can be then injected into spinnaker pipelines via h...

Published: Jan 05, 2026
Source: NVD