[rogerace](https://hackerone.com/rogerace)
15 credited records · 11 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
17Monitor | CVE-2026-8937No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.3% | 1 day ago |
17Monitor | CVE-2026-10518No exploit | Incorrect Authorization in GitLabgitlab · gitlab · CWE-863 | Medium4.3 | — | 0.3% | 1 day ago |
14Monitor | CVE-2026-7487No exploit | Access Control Check Implemented After Asset is Accessed in GitLabgitlab · gitlab · CWE-1280 | Low3.5 | — | 0.3% | Aug 26, 2026 |
17Monitor | CVE-2026-6821No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.4% | Aug 12, 2026 |
17Monitor | CVE-2026-4672No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.4% | Jul 29, 2026 |
19Monitor | CVE-2026-11827No exploit | Insufficiently Protected Credentials in GitLabgitlab · gitlab · CWE-522 | Medium4.9 | — | 0.4% | Jul 8, 2026 |
21Monitor | CVE-2026-6269No exploit | Incorrect Authorization in GitLabgitlab · gitlab · CWE-863 | Medium5.4 | — | 0.3% | Jun 11, 2026 |
17Monitor | CVE-2026-5296No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.3% | May 27, 2026 |
14Monitor | CVE-2025-3950No exploit | Exposure of Private Personal Information to an Unauthorized Actor in GitLabgitlab · gitlab · CWE-359 | Low3.5 | — | 0.3% | Jan 9, 2026 |
14Monitor | CVE-2025-6945No exploit | Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabgitlab · gitlab · CWE-77 | Low3.5 | — | 0.3% | Nov 15, 2025 |
26Monitor | CVE-2025-2615No exploit | Insertion of Sensitive Information Into Sent Data in GitLabgitlab · gitlab · CWE-201 | Medium6.5 | — | 0.3% | Nov 15, 2025 |
35Monitor | CVE-2025-7691No exploit | Privilege Defined With Unsafe Actions in GitLabgitlab · gitlab · CWE-267 | High8.8 | — | 0.4% | Sep 26, 2025 |
17Monitor | CVE-2025-2498No exploit | Insufficient Granularity of Access Control in GitLabgitlab · gitlab · CWE-1220 | Medium4.3 | — | 0.3% | Aug 13, 2025 |
21Monitor | CVE-2025-4976No exploit | Exposure of Sensitive Information Due to Incompatible Policies in GitLabgitlab · gitlab · CWE-213 | Medium5.3 | — | 0.4% | Jul 24, 2025 |
21Monitor | CVE-2025-2408No exploit | Insufficient Granularity of Access Control in GitLabgitlab · gitlab · CWE-1220 | Medium5.3 | — | 0.3% | Apr 10, 2025 |
- CVE-2026-893717Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlab1 day ago
- CVE-2026-1051817Monitor
Incorrect Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlab1 day ago
- CVE-2026-748714Monitor
Access Control Check Implemented After Asset is Accessed in GitLab
LowCVSS 3.5No exploitEPSS 0%gitlab · gitlabAug 26, 2026
- CVE-2026-682117Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabAug 12, 2026
- CVE-2026-467217Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabJul 29, 2026
- CVE-2026-1182719Monitor
Insufficiently Protected Credentials in GitLab
MediumCVSS 4.9No exploitEPSS 0%gitlab · gitlabJul 8, 2026
- CVE-2026-626921Monitor
Incorrect Authorization in GitLab
MediumCVSS 5.4No exploitEPSS 0%gitlab · gitlabJun 11, 2026
- CVE-2026-529617Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabMay 27, 2026
- CVE-2025-395014Monitor
Exposure of Private Personal Information to an Unauthorized Actor in GitLab
LowCVSS 3.5No exploitEPSS 0%gitlab · gitlabJan 9, 2026
- CVE-2025-694514Monitor
Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
LowCVSS 3.5No exploitEPSS 0%gitlab · gitlabNov 15, 2025
- CVE-2025-261526Monitor
Insertion of Sensitive Information Into Sent Data in GitLab
MediumCVSS 6.5No exploitEPSS 0%gitlab · gitlabNov 15, 2025
- CVE-2025-769135Monitor
Privilege Defined With Unsafe Actions in GitLab
HighCVSS 8.8No exploitEPSS 0%gitlab · gitlabSep 26, 2025
- CVE-2025-249817Monitor
Insufficient Granularity of Access Control in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabAug 13, 2025
- CVE-2025-497621Monitor
Exposure of Sensitive Information Due to Incompatible Policies in GitLab
MediumCVSS 5.3No exploitEPSS 0%gitlab · gitlabJul 24, 2025
- CVE-2025-240821Monitor
Insufficient Granularity of Access Control in GitLab
MediumCVSS 5.3No exploitEPSS 0%gitlab · gitlabApr 10, 2025