CVE 列表 – 发现高风险与在野利用漏洞

聚合 NVD、CVE 及多源情报,深度解析 RCE 等高危风险。系统集成 CVSS 与 EPSS 模型,动态追踪 Exploit 资源与 PoC 公开状态,研判可利用性。结合官方补丁与修复方案,优化漏洞管理优先级,缩短响应周期,保障资产安全。

分配机构(CNA / 来源):[email protected] 移除此筛选

显示 41601528 条结果
CVE 描述 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-4868 GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's identity due to improper user identity resolution when triggering Duo AI workflow runners. 8.2 0.28% 2026-05-27 2026-06-17
CVE-2026-2601 GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to access sensitive deployment data on projects due to improper authorization checks. 4.3 0.24% 2026-05-27 2026-06-17
CVE-2026-1402 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authenticated user to cause denial of service due to insufficient validation. 6.5 0.47% 2026-05-27 2026-06-17
CVE-2026-8680 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. 2026-05-26 2026-05-26
CVE-2026-5297 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. 2026-05-21 2026-05-21
CVE-2026-8399 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. 2026-05-20 2026-05-20
CVE-2026-6050 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. 2026-05-16 2026-05-16
CVE-2026-8280 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to cause denial of service through excessive memory consumption due to improper input validation. 6.5 0.29% 2026-05-14 2026-06-17
CVE-2026-8144 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with project membership to enumerate private group members due to missing authorization checks. 4.3 0.17% 2026-05-14 2026-06-17
CVE-2026-7481 GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization. 8.7 0.26% 2026-05-14 2026-06-17
CVE-2026-7471 GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper validation. 3.5 0.17% 2026-05-14 2026-06-17
CVE-2026-7377 GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization. 8.7 0.26% 2026-05-14 2026-06-17
CVE-2026-6883 GitLab has remediated an issue in GitLab EE affecting all versions from 15.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to bypass merge request approval requirements due to improper cleanup of orphaned policy records. 2.6 0.15% 2026-05-14 2026-06-17
CVE-2026-6335 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization. 5.4 0.19% 2026-05-14 2026-06-17
CVE-2026-6073 GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to execute arbitrary JavaScript in other users' browsers due to improper input sanitization. 8.7 0.19% 2026-05-14 2026-06-17
CVE-2026-6063 GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user with developer-role permissions to remove code owner approval rules from merge requests due to improper access control. 4.3 0.19% 2026-05-14 2026-06-17
CVE-2026-4527 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to create unauthorized Jira subscriptions for a targeted user's namespace via a specially crafted link due to missing CSRF protection. 6.5 0.15% 2026-05-14 2026-06-17
CVE-2026-4524 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to access confidential issue content in public projects without proper authorization due to improper authorization checks. 6.5 0.29% 2026-05-14 2026-06-17
CVE-2026-3607 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to bypass package protection rules due to improper access control. 4.3 0.23% 2026-05-14 2026-06-17
CVE-2026-3160 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter functioning only as a display control rather than enforcing access boundaries as specified. 5.8 0.22% 2026-05-14 2026-06-17
cvelogic Threat Intelligence