Search CVE reports


Toggle filters

601 – 610 of 48251 results

Status is adjusted based on your filters.


CVE-2026-0602

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to disclose metadata from private issues,...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-14513

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an unauthenticated user to cause a denial of service condition due...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-13690

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.11 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to cause a denial of service condition due to...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-12697

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2025-12576

Medium priority
Ignored

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that under certain conditions could have allowed an authenticated user to cause a denial of...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2026-3904

Medium priority
Not affected

Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library version 2.36 under high load on x86_64 systems, the client may call memcmp on inputs that are concurrently...

2 affected packages

glibc, eglibc

Package 16.04 LTS
glibc Not affected
eglibc
Show less packages

CVE-2026-3884

Medium priority
Needs evaluation

Versions of the package spin.js before 3.0.0 are vulnerable to Cross-site Scripting (XSS) via the spin() function that allows a creation of more than 1 alert for each 'target' element. An attacker would need to set an arbitrary...

1 affected package

libjs-spin.js

Package 16.04 LTS
libjs-spin.js Needs evaluation
Show less packages

CVE-2026-23868

Medium priority
Needs evaluation

Giflib contains a double-free vulnerability that is the result of a shallow copy in GifMakeSavedImage and incorrect error handling. The conditions needed to trigger this vulnerability are difficult but may be possible.

1 affected package

giflib

Package 16.04 LTS
giflib Needs evaluation
Show less packages

CVE-2025-70129

Medium priority
Needs evaluation

If the anti spam-captcha functionality in PluXml versions 5.8.22 and earlier is enabled, a captcha challenge is generated with a format that can be automatically recognized for articles, such that an automated script is able to...

1 affected package

pluxml

Package 16.04 LTS
pluxml Needs evaluation
Show less packages

CVE-2025-70128

Medium priority
Needs evaluation

A Stored Cross-Site Scripting (XSS) vulnerability exists in the PluXml article comments feature for PluXml versions 5.8.22 and earlier. The application fails to properly sanitize or validate user-supplied input in the "link" field...

1 affected package

pluxml

Package 16.04 LTS
pluxml Needs evaluation
Show less packages