gitlab kayıtları
gitlab üreticisine ait 1.481 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 5 · %0,3
- Silahlaştırılmış
- 11 · %0,7
- Pre-auth RCE
- 26
- Düzeltme kaydı olan
- %42
- Yayından KEV’e ortanca
- 194 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')180
- CWE-863 Incorrect Authorization129
- CWE-770 Allocation of Resources Without Limits or Throttling93
- CWE-862 Missing Authorization81
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor63
- CWE-400 Uncontrolled Resource Consumption48
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
1.481 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-22205Silahlaştırılmış | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Kritik10,0 | KEV | %99,7 | 23 Nis 2021 |
97Hemen | CVE-2023-7028Silahlaştırılmış | Weak Password Recovery Mechanism for Forgotten Password in GitLabgitlab · gitlab · CWE-640 | Kritik9,8 | KEV | %94,6 | 12 Oca 2024 |
97Hemen | CVE-2026-85706Silahlaştırılmış | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab · gitlab · CWE-22 | Kritik10,0 | KEV | %91,4 | 11 Eyl 2026 |
85Hemen | CVE-2021-22175Silahlaştırılmış | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versionsgitlab · gitlab · CWE-918 | Kritik9,8 | KEV | %53,4 | 11 Haz 2021 |
71Bu hafta | CVE-2021-39935Silahlaştırılmış | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 beforegitlab · gitlab · CWE-918 | Yüksek7,5 | KEV | %35,6 | 13 Ara 2021 |
65Bu hafta | CVE-2022-2992Silahlaştırılmış | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated usgitlab · gitlab · CWE-74 | Kritik9,9 | — | %86,2 | 17 Eki 2022 |
62Bu hafta | CVE-2022-2884Kavram kanıtı | A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authgitlab · gitlab · CWE-78 | Kritik9,9 | — | %75,7 | 17 Eki 2022 |
62Bu hafta | CVE-2022-1162Kavram kanıtı | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.gitlab · gitlab · CWE-798 | Kritik9,8 | — | %75,6 | 4 Nis 2022 |
58Planlayın | CVE-2022-2185Kavram kanıtı | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prgitlab · gitlab · CWE-78 | Yüksek8,8 | — | %76,7 | 1 Tem 2022 |
55Planlayın | CVE-2020-13340İstismar yok | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Loggitlab · gitlab · CWE-79 | Yüksek8,7 | — | %68,6 | 8 Eki 2020 |
54Planlayın | CVE-2026-19478Kavram kanıtı | Improper Control of Generation of Code ('Code Injection') in GitLabgitlab · gitlab · CWE-94 | Kritik9,1 | — | %60,2 | 17 Ağu 2026 |
54Planlayın | CVE-2018-14364İstismar yok | GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write acgitlab · gitlab · CWE-22 | Kritik9,8 | — | %50,1 | 18 Tem 2018 |
51Planlayın | CVE-2023-2825Silahlaştırılmış | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.gitlab · gitlab · CWE-22 | Yüksek7,5 | — | %71,6 | 26 May 2023 |
50Planlayın | CVE-2023-2442İstismar yok | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befogitlab · gitlab · CWE-79 | Orta5,4 | — | %96,1 | 7 Haz 2023 |
49Planlayın | CVE-2023-0050İstismar yok | An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.gitlab · gitlab · CWE-79 | Orta5,4 | — | %92,4 | 9 Mar 2023 |
49Planlayın | CVE-2022-1175Kavram kanıtı | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versiogitlab · gitlab · CWE-79 | Orta6,1 | — | %82,0 | 4 Nis 2022 |
49Planlayın | CVE-2024-1451İstismar yok | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | Yüksek8,7 | — | %51,5 | 21 Şub 2024 |
47Planlayın | CVE-2022-1190İstismar yok | Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attagitlab · gitlab · CWE-79 | Orta5,4 | — | %87,4 | 4 Nis 2022 |
47Planlayın | CVE-2022-3265İstismar yok | A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 priogitlab · gitlab · CWE-79 | Orta5,4 | — | %86,3 | 9 Kas 2022 |
45Planlayın | CVE-2021-4191Silahlaştırılmış | An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.gitlab · gitlab | Orta5,3 | — | %80,0 | 28 Mar 2022 |
43Planlayın | CVE-2021-22238İstismar yok | An issue has been discovered in GitLab affecting all versions starting with 13.3.gitlab · gitlab · CWE-79 | Orta5,4 | — | %71,8 | 20 Ağu 2021 |
43Planlayın | CVE-2023-3364İstismar yok | Inefficient Regular Expression Complexity in GitLabgitlab · gitlab · CWE-1333 | Yüksek7,5 | — | %44,5 | 1 Ağu 2023 |
43Planlayın | CVE-2022-0735Kavram kanıtı | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 beforgitlab · gitlab | Kritik9,8 | — | %13,2 | 28 Mar 2022 |
43Planlayın | CVE-2025-5121İstismar yok | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Kritik9,9 | — | %12,4 | 20 Haz 2025 |
42Planlayın | CVE-2023-0921İstismar yok | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | Orta4,3 | — | %84,4 | 6 Haz 2023 |
- CVE-2021-22205100Hemen
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100gitlab · gitlab23 Nis 2021
- CVE-2023-702897Hemen
Weak Password Recovery Mechanism for Forgotten Password in GitLab
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95gitlab · gitlab12 Oca 2024
- CVE-2026-8570697Hemen
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %91gitlab · gitlab11 Eyl 2026
- CVE-2021-2217585Hemen
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %53gitlab · gitlab11 Haz 2021
- CVE-2021-3993571Bu hafta
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %36gitlab · gitlab13 Ara 2021
- CVE-2022-299265Bu hafta
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us
KritikCVSS 9,9SilahlaştırılmışEPSS %86gitlab · gitlab17 Eki 2022
- CVE-2022-288462Bu hafta
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an auth
KritikCVSS 9,9Kavram kanıtıEPSS %76gitlab · gitlab17 Eki 2022
- CVE-2022-116262Bu hafta
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
KritikCVSS 9,8Kavram kanıtıEPSS %76gitlab · gitlab4 Nis 2022
- CVE-2022-218558Planlayın
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 pr
YüksekCVSS 8,8Kavram kanıtıEPSS %77gitlab · gitlab1 Tem 2022
- CVE-2020-1334055Planlayın
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
YüksekCVSS 8,7İstismar yokEPSS %69gitlab · gitlab8 Eki 2020
- CVE-2026-1947854Planlayın
Improper Control of Generation of Code ('Code Injection') in GitLab
KritikCVSS 9,1Kavram kanıtıEPSS %60gitlab · gitlab17 Ağu 2026
- CVE-2018-1436454Planlayın
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write ac
KritikCVSS 9,8İstismar yokEPSS %50gitlab · gitlab18 Tem 2018
- CVE-2023-282551Planlayın
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.
YüksekCVSS 7,5SilahlaştırılmışEPSS %72gitlab · gitlab26 May 2023
- CVE-2023-244250Planlayın
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befo
OrtaCVSS 5,4İstismar yokEPSS %96gitlab · gitlab7 Haz 2023
- CVE-2023-005049Planlayın
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.
OrtaCVSS 5,4İstismar yokEPSS %92gitlab · gitlab9 Mar 2023
- CVE-2022-117549Planlayın
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versio
OrtaCVSS 6,1Kavram kanıtıEPSS %82gitlab · gitlab4 Nis 2022
- CVE-2024-145149Planlayın
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
YüksekCVSS 8,7İstismar yokEPSS %51gitlab · gitlab21 Şub 2024
- CVE-2022-119047Planlayın
Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an atta
OrtaCVSS 5,4İstismar yokEPSS %87gitlab · gitlab4 Nis 2022
- CVE-2022-326547Planlayın
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prio
OrtaCVSS 5,4İstismar yokEPSS %86gitlab · gitlab9 Kas 2022
- CVE-2021-419145Planlayın
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.
OrtaCVSS 5,3SilahlaştırılmışEPSS %80gitlab · gitlab28 Mar 2022
- CVE-2021-2223843Planlayın
An issue has been discovered in GitLab affecting all versions starting with 13.3.
OrtaCVSS 5,4İstismar yokEPSS %72gitlab · gitlab20 Ağu 2021
- CVE-2023-336443Planlayın
Inefficient Regular Expression Complexity in GitLab
YüksekCVSS 7,5İstismar yokEPSS %44gitlab · gitlab1 Ağu 2023
- CVE-2022-073543Planlayın
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 befor
KritikCVSS 9,8Kavram kanıtıEPSS %13gitlab · gitlab28 Mar 2022
- CVE-2025-512143Planlayın
Missing Authorization in GitLab
KritikCVSS 9,9İstismar yokEPSS %12gitlab · gitlab20 Haz 2025
- CVE-2023-092142Planlayın
Allocation of Resources Without Limits or Throttling in GitLab
OrtaCVSS 4,3İstismar yokEPSS %84gitlab · gitlab6 Haz 2023