Known vulnerabilities in GitLab Enterprise Edition - page 15

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU109654 - Improper Access Control
CVE-2025-1110
CWE-284 Low
No
No
18.0.1 22.05.2025 SB2025052223
#VU109653 - Exposure of sensitive information to an unauthorized actor
CVE-2024-9163
CWE-200 Low
No
No
12.1.1, 12.1.2, 12.1.3, 12.1.4, 12.1.5, 12.1.9, 12.1.10, 12.1.12, 12.1.14, 12.2.0, 12.2.1, 12.2.2, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.11, 12.3.0, 12.3.1, 12.3.2, 12.3.4, 12.3.7, 12.3.9, 12.4.0, 12.4.1, 12.4.2, 12.4.3, 12.4.5, 12.4.8, 12.5.0, 12.5.1, 12.5.3, 12.5.4, 12.5.5, 12.5.8, 12.5.9, 12.6.0, 12.6.1, 12.6.2, 12.6.4, 12.6.5, 12.6.6, 12.6.7, 12.7.0, 12.7.1, 12.7.2, 12.7.3, 12.7.4, 12.7.5, 12.7.9, 12.8.0, 12.8.1, 12.8.2, 12.8.3, 12.8.4, 12.8.5, 12.8.6, 12.8.7, 12.8.9, 12.8.10, 12.9.0, 12.9.1, 12.9.2, 12.9.3, 12.9.4, 12.9.5, 12.9.6, 12.9.8, 12.9.10, 12.10.0, 12.10.1, 12.10.2, 12.10.4, 12.10.5, 12.10.6, 12.10.7, 12.10.8, 12.10.11, 12.10.12, 12.10.13, 12.10.14, 13.0.0, 13.0.1, 13.0.3, 13.0.4, 13.0.6, 13.0.7, 13.0.8, 13.0.9, 13.0.10, 13.0.11, 13.0.12, 13.0.13, 13.0.14, 13.1.0, 13.1.1, 13.1.2, 13.1.3, 13.1.5, 13.1.6, 13.1.7, 13.1.8, 13.1.9, 13.1.10, 13.2.0, 13.2.2, 13.2.3, 13.2.4, 13.2.5, 13.2.6, 13.2.7, 13.2.8, 13.2.10, 13.3.0, 13.3.1, 13.3.2, 13.3.3, 13.3.4, 13.3.5, 13.3.6, 13.3.7, 13.3.8, 13.3.9, 13.4.0, 13.4.2, 13.4.3, 13.4.4, 13.4.5, 13.4.6, 13.4.7, 13.5.0, 13.5.1, 13.5.2, 13.5.3, 13.5.4, 13.5.5, 13.5.6, 13.5.7, 13.6.0, 13.6.1, 13.6.2, 13.6.3, 13.6.4, 13.6.5, 13.6.6, 13.6.7, 13.7.0, 13.7.1, 13.7.2, 13.7.3, 13.7.4, 13.7.5, 13.7.6, 13.7.7, 13.7.8, 13.7.9, 13.8.0, 13.8.1, 13.8.2, 13.8.3, 13.8.4, 13.8.5, 13.8.6, 13.8.7, 13.8.8, 13.9.0, 13.9.1, 13.9.2, 13.9.3, 13.9.4, 13.9.5, 13.9.6, 13.9.7, 13.10.0, 13.10.1, 13.10.2, 13.10.3, 13.10.4, 13.10.5, 13.11.0, 13.11.1, 13.11.2, 13.11.3, 13.11.4, 13.11.5, 13.11.6, 13.11.7, 13.12.0, 13.12.1, 13.12.2, 13.12.3, 13.12.4, 13.12.5, 13.12.6, 13.12.7, 13.12.8, 13.12.9, 13.12.10, 13.12.11, 13.12.12, 13.12.13, 13.12.14, 13.12.15, 14.0.0, 14.0.1, 14.0.2, 14.0.3, 14.0.4, 14.0.5, 14.0.6, 14.0.7, 14.0.8, 14.0.9, 14.0.10, 14.0.11, 14.0.12, 14.1.0, 14.1.1, 14.1.2, 14.1.3, 14.1.4, 14.1.5, 14.1.6, 14.1.7, 14.1.8, 14.2.0, 14.2.1, 14.2.2, 14.2.3, 14.2.4, 14.2.5, 14.2.6, 14.2.7, 14.3.0, 14.3.1, 14.3.2, 14.3.3, 14.3.4, 14.3.5, 14.3.6, 14.4.0, 14.4.1, 14.4.2, 14.4.3, 14.4.4, 14.4.5, 14.5.0, 14.5.1, 14.5.2, 14.5.3, 14.5.4, 14.6.0, 14.6.1, 14.6.2, 14.6.3, 14.6.4, 14.6.5, 14.6.6, 14.6.7, 14.7.0, 14.7.1, 14.7.2, 14.7.3, 14.7.4, 14.7.5, 14.7.6, 14.7.7, 14.8.0, 14.8.1, 14.8.2, 14.8.3, 14.8.4, 14.8.5, 14.8.6, 14.9.0, 14.9.1, 14.9.2, 14.9.3, 14.9.4, 14.9.5, 14.10.0, 14.10.1, 14.10.2, 14.10.3, 14.10.4, 14.10.5, 15.0.0, 15.0.1, 15.0.2, 15.0.3, 15.0.4, 15.0.5, 15.1.0, 15.1.1, 15.1.2, 15.1.3, 15.1.4, 15.1.5, 15.1.6, 15.2.0, 15.2.1, 15.2.2, 15.2.3, 15.2.4, 15.2.5, 15.3.0, 15.3.1, 15.3.2, 15.3.3, 15.3.4, 15.3.5, 15.4.0, 15.4.1, 15.4.2, 15.4.3, 15.4.4, 15.4.5, 15.4.6, 15.5.0, 15.5.1, 15.5.2, 15.5.3, 15.5.4, 15.5.5, 15.5.6, 15.5.7, 15.5.8, 15.5.9, 15.6.0, 15.6.1, 15.6.2, 15.6.3, 15.6.4, 15.6.5, 15.6.6, 15.6.7, 15.6.8, 15.7.0, 15.7.1, 15.7.2, 15.7.3, 15.7.4, 15.7.5, 15.7.6, 15.7.7, 15.7.8, 15.7.9, 15.8.0, 15.8.1, 15.8.2, 15.8.3, 15.8.4, 15.8.5, 15.8.6, 15.9.0, 15.9.1, 15.9.2, 15.9.3, 15.9.4, 15.9.5, 15.9.6, 15.9.7, 15.9.8, 15.10.0, 15.10.1, 15.10.2, 15.10.3, 15.10.4, 15.10.5, 15.10.6, 15.10.7, 15.10.8, 15.11.0, 15.11.1, 15.11.2, 15.11.3, 15.11.4, 15.11.5, 15.11.6, 15.11.7, 15.11.8, 15.11.9, 15.11.10, 15.11.11, 15.11.12, 15.11.13, 16.0.0, 16.0.1, 16.0.2, 16.0.3, 16.0.4, 16.0.5, 16.0.6, 16.0.7, 16.0.8, 16.0.9, 16.0.10, 16.1.0, 16.1.1, 16.1.2, 16.1.3, 16.1.4, 16.1.5, 16.1.6, 16.1.7, 16.1.8, 16.2.0, 16.2.1, 16.2.2, 16.2.3, 16.2.4, 16.2.5, 16.2.6, 16.2.7, 16.2.8, 16.2.9, 16.2.10, 16.2.11, 16.3.0, 16.3.1, 16.3.2, 16.3.3, 16.3.4, 16.3.5, 16.3.6, 16.3.7, 16.3.8, 16.3.9, 16.4.0, 16.4.1, 16.4.2, 16.4.3, 16.4.4, 16.4.5, 16.4.6, 16.4.7, 16.5.0, 16.5.1, 16.5.2, 16.5.3, 16.5.4, 16.5.5, 16.5.6, 16.5.7, 16.5.8, 16.5.9, 16.5.10, 16.6.0, 16.6.1, 16.6.2, 16.6.3, 16.6.4, 16.6.5, 16.6.6, 16.6.7, 16.6.8, 16.6.9, 16.6.10, 16.7.0, 16.7.1, 16.7.2, 16.7.3, 16.7.4, 16.7.5, 16.7.6, 16.7.7, 16.7.8, 16.7.9, 16.7.10, 16.8.0, 16.8.1, 16.8.2, 16.8.3, 16.8.4, 16.8.5, 16.8.6, 16.8.7, 16.8.8, 16.8.9, 16.8.10, 16.9.0, 16.9.1, 16.9.2, 16.9.3, 16.9.4, 16.9.5, 16.9.6, 16.9.7, 16.9.8, 16.9.9, 16.9.10, 16.9.11, 16.10.0, 16.10.1, 16.10.2, 16.10.3, 16.10.4, 16.10.5, 16.10.6, 16.10.7, 16.10.8, 16.10.9, 16.10.10, 16.11.0, 16.11.1, 16.11.2, 16.11.3, 16.11.4, 16.11.5, 16.11.6, 16.11.7, 16.11.8, 16.11.9, 16.11.10, 17.0.0, 17.0.1, 17.0.2, 17.0.3, 17.0.4, 17.0.5, 17.0.6, 17.0.7, 17.0.8, 17.1.0, 17.1.1, 17.1.2, 17.1.3, 17.1.4, 17.1.5, 17.1.6, 17.1.7, 17.1.8, 17.2.0, 17.2.1, 17.2.2, 17.2.3, 17.2.4, 17.2.5, 17.2.6, 17.2.7, 17.2.8, 17.2.9, 17.3.0, 17.3.1, 17.3.2, 17.3.3, 17.3.4, 17.3.5, 17.3.6, 17.3.7, 17.4.0, 17.4.1, 17.4.2, 17.4.3, 17.4.4, 17.4.5, 17.4.6, 17.5.0, 17.5.1, 17.5.2, 17.5.3, 17.5.4, 17.5.5, 17.6.0, 17.6.1, 17.6.2, 17.6.3, 17.6.4, 17.6.5, 17.7.0, 17.7.1, 17.7.2, 17.7.3, 17.7.4, 17.7.5, 17.7.6, 17.7.7, 17.8.0, 17.8.1, 17.8.2, 17.8.3, 17.8.4, 17.8.5, 17.8.6, 17.8.7, 17.9.0, 17.9.1, 17.9.2, 17.9.3, 17.9.4, 17.9.5, 17.9.6, 17.9.7, 17.9.8, 17.10.0, 17.10.1, 17.10.2, 17.10.3, 17.10.4, 17.10.5, 17.10.6, 17.10.7, 17.11.0, 17.11.1, 17.11.2, 17.11.3, 18.0.1 22.05.2025 SB2025052223
#VU109652 - Exposure of sensitive information to an unauthorized actor
CVE-2025-0679
CWE-200 Low
No
No
17.10.7, 17.11.3, 18.0.1 22.05.2025 SB2025052223
#VU109650 - Security Features
CVE-2025-0605
CWE-254 Low
No
No
17.10.7, 17.11.3, 18.0.1 22.05.2025 SB2025052223
#VU109649 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4979
CWE-200 Low
No
No
17.10.7, 17.11.3, 18.0.1 22.05.2025 SB2025052223
#VU108782 - Improper Access Control
CVE-2025-1278
CWE-284 Medium
No
No
17.9.8, 17.10.6, 17.11.2 08.05.2025 SB2025050804
#VU108781 - Resource exhaustion
CVE-2024-8973
CWE-400 Medium
No
No
17.9.8, 17.10.6, 17.11.2 08.05.2025 SB2025050804
#VU108780 - Improper Authentication
CVE-2025-0549
CWE-287 High
No
No
17.9.8, 17.10.6, 17.11.2 08.05.2025 SB2025050804
#VU107884 - Improper Access Control
CVE-2024-12244
CWE-284 Low
No
No
17.9.7, 17.10.5, 17.11.1 23.04.2025 SB2025042341
#VU107883 - Resource exhaustion
CVE-2025-0639
CWE-400 Medium
No
No
17.9.7, 17.10.5, 17.11.1 23.04.2025 SB2025042341
#VU107882 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2025-1908
CWE-644 Medium
No
No
17.9.7, 17.10.5, 17.11.1 23.04.2025 SB2025042341
#VU107881 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-2443
CWE-79 Low
No
No
17.9.7, 17.10.5, 17.11.1 23.04.2025 SB2025042341
#VU107880 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-1763
CWE-79 Low
No
No
17.9.7, 17.10.5, 17.11.1 23.04.2025 SB2025042341
#VU107340 - Exposure of sensitive information to an unauthorized actor
CVE-2025-2469
CWE-200 Medium
No
No
17.9.6, 17.10.4 10.04.2025 SB2025041015
#VU107339 - Exposure of sensitive information to an unauthorized actor
CVE-2024-11129
CWE-200 Medium
No
No
17.8.7, 17.9.6, 17.10.4 10.04.2025 SB2025041015
#VU107338 - Exposure of sensitive information to an unauthorized actor
CVE-2025-2408
CWE-200 Medium
No
No
17.8.7, 17.9.6, 17.10.4 10.04.2025 SB2025041015
#VU107337 - Improper Access Control
CVE-2025-0362
CWE-284 Medium
No
No
17.8.7, 17.9.6, 17.10.4 10.04.2025 SB2025041015
#VU107336 - Improper input validation
CVE-2025-1677
CWE-20 Medium
No
No
17.8.7, 17.9.6, 17.10.4 10.04.2025 SB2025041015
#VU106072 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-0811
CWE-79 Low
No
No
17.8.6, 17.9.3, 17.10.1 27.03.2025 SB2025032702
#VU106071 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2025-2255
CWE-79 Low
No
No
17.8.6, 17.9.3, 17.10.1 27.03.2025 SB2025032702


Showing elements 281 - 300 out of 1052