Total
395675 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-89158 | 1 Pcre | 1 Pcre2 | 2026-09-16 | N/A | 6.5 MEDIUM |
| PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write. | |||||
| CVE-2026-86341 | 2026-09-16 | N/A | 4.4 MEDIUM | ||
| GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user with Owner or Maintainer permissions could have silently disabled protected environment deployment approval requirements, allowing unapproved deployments to reach production, due to improper access control checks performed after the protected resource was modified. | |||||
| CVE-2026-1168 | 2026-09-16 | N/A | 7.5 HIGH | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic. | |||||
| CVE-2026-16794 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with the Security Manager role to execute arbitrary CI/CD jobs and access protected variables within group projects due to improper authorization controls on compliance framework management. | |||||
| CVE-2026-87719 | 2026-09-16 | N/A | 9.9 CRITICAL | ||
| GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and sensitive credentials using a specially crafted GraphQL subscription argument to bypass serialization and perform server object lookup. | |||||
| CVE-2026-79708 | 2026-09-16 | N/A | 8.5 HIGH | ||
| GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects within their group and access protected CI/CD variables restricted to higher-privileged roles, due to insufficient scope validation. | |||||
| CVE-2026-8030 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user to prevent another user from modifying their group settings due to improper validation of group URL slugs during namespace transfers. | |||||
| CVE-2026-88765 | 2026-09-16 | N/A | 8.5 HIGH | ||
| GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing. | |||||
| CVE-2026-3855 | 2026-09-16 | N/A | 3.1 LOW | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticated user with project-level permissions to access restricted file contents on the server or cause denial of service due to improper validation of parameters in the Terraform state upload functionality. | |||||
| CVE-2026-19619 | 2026-09-16 | N/A | 4.7 MEDIUM | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor. | |||||
| CVE-2026-78252 | 2026-09-16 | N/A | 8.2 HIGH | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer. | |||||
| CVE-2025-14871 | 2026-09-16 | N/A | 7.5 HIGH | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation limits in the GraphQL complexity calculation logic. | |||||
| CVE-2026-7514 | 2026-09-16 | N/A | 4.3 MEDIUM | ||
| GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions could substitute package file content and hide packages from their owners due to improper authorization checks in the Generic Package Registry. | |||||
| CVE-2026-66304 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 7.5 HIGH |
| Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network. | |||||
| CVE-2026-66303 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 6.5 MEDIUM |
| Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. | |||||
| CVE-2026-66302 | 1 Microsoft | 2 Skype For Business Server, Skype For Business Server Subscription Edition | 2026-09-16 | N/A | 9.8 CRITICAL |
| External control of file name or path in Skype for Business allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-16186 | 2026-09-16 | N/A | 5.4 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 is affected by a reflected cross-site scripting vulnerability. | |||||
| CVE-2026-17467 | 2026-09-16 | N/A | 8.2 HIGH | ||
| IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a remote attacker to obtain sensitive information due to the use of weak or deprecated cryptographic protocols. | |||||
| CVE-2026-16187 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication and obtain sensitive information by sending a crafted unauthenticated request. | |||||
| CVE-2026-17463 | 2026-09-16 | N/A | 6.5 MEDIUM | ||
| IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption. | |||||
