| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Original HTTPS Page] |
Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.
You must be logged in to block users.
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abuse| N° | CVE | Severity | Target | Description |
|---|---|---|---|---|
| 38 | CVE-2026-15423 | High | GitLab CE/EE | Improper Authorization issue in CI/CD pipeline API impacts GitLab CE/EE - GitLab Patch Release |
| 37 | CVE-2026-1101 | Medium | GitLab EE | Denial of Service issue in GraphQL SBOM API - GitLab Patch Release |
| 36 | CVE-2026-1388 | High | GitLab CE/EE | Regular Expression Denial of Service issue in GitLab merge requests - GitLab Patch Release |
| N° | CVE | Severity | Target | Description |
|---|---|---|---|---|
| 35 | CVE-2025-12576 | Medium | GitLab CE/EE | Denial of Service issue in webhook endpoint - GitLab Patch Release |
| 34 | CVE-2025-13690 | Medium | GitLab CE/EE | Denial of Service issue in webhook custom headers - GitLab Patch Release - H1 Report - advisory |
| 33 | CVE-2025-13335 | Medium | GitLab CE/EE | Crafted wiki file may lead to endless server-side redirections - Bleeping Computer |
| 32 | CVE-2025-0673 | High | GitLab CE/EE | An attacker can trigger an infinite redirect loop, leading to a denial of service condition - Patch Release |
| 31 | GHSA-6p2v-wcv8-8j6w | Critical | Caido Plugin | Arbitrary File Read by Copy as a Curl command in Caido Plugin Exploit Generator - advisory |
| 30 | CVE-2025-0549 | Medium | GitLab | Partial Bypass for Device OAuth flow using Cross Window Forgery |
| 29 | CVE-2025-31116 | Medium | MobSF | SSRF on assetlinks_check with DNS Rebinding |
| N° | CVE | Severity | Target | Description |
|---|---|---|---|---|
| 28 | CVE-2024-13054 | Medium | GitLab CE/EE | Denial of Service Due to Inefficient Processing of Untrusted Input - GitLab Patch Release |
| 27 | CVE-2024-12379 | Medium | GitLab CE/EE | Denial of Service due to Unbounded Symbol Creation via the scopes parameter in a Personal Access Token |
| 26 | CVE-2024-47830 | Critical | Plane | Server side request forgery via /_next/image endpoint |
| 25 | CVE-2024-8124 | High | GitLab | Denial of Service via sending a large glm_source parameter - GitLab Patch Release |
| 24 | CVE-2024-45412 | Medium | Yeti Platform | Potential Denial of Service due to the One Million Unicode Characters attack |
| 23 | CVE-2024-35231 | High | Rack::Contrib | Denial of Service due to the unconstrained value of the incoming "profiler_runs" parameter |
| 22 | CVE-2024-1211 | Medium | GitLab | Require confirmation before linking JWT identity - GitLab Blog |
| 21 | GHSA-9gw7-hxgx-f6rv | Medium | FAME (Cert SG) | Malicious Long Unicode filenames may cause an Application-level Denial of Service |
| 20 | CVE-2024-32874 | Medium | Frigate | Malicious Long Unicode filenames may cause Multiple Application-level Denial of Service |
| 19 | CVE-2024-0081 | High | NVIDIA NeMo | Unicode use in a user-controlled filename may cause a server-side DoS - Nvidia Acknowledgement |
| 18 | CVE-2024-24759 | Critical | MindsDB | Bypass SSRF Protection with DNS Rebinding |
| 17 | CVE-2024-23826 | Medium | SPbU SE Site | Uploading an image with a specific filename causes a server-side DoS |
| 16 | CVE-2024-21623 | Critical | OTClient | Arbitrary Expression Injection in GitHub workflow leads to Command execution & leaking secrets |
| N° | CVE | Severity | Target | Description |
|---|---|---|---|---|
| 15 | CVE-2023-52081 | Low | ffcss | Late-Unicode normalization vulnerability |
| 14 | CVE-2023-41889 | Medium | Shirasagi | Late-Unicode normalization vulnerability - advisory |
| 13 | CVE-2023-42183 | Low | LOCKSS | A Post-Unicode Normalization Vulnerability - advisory |
| 12 | GHSA-373w-rj84-pv6x | Low | safeurl-python | Hostname blocklist does not block FQDNs - advisory |
| 11 | CVE-2023-35932 | High | jcvi | Configuration Injection due to unsanitized user input - advisory |
| 10 | CVE-2023-31131 | High | Greenplum DB | Arbitrary File Write (path traversal) when extracting tar files within GPPKGs |
| 9 | CVE-2023-30620 | High | MindsDB | Arbitrary File Write when Extracting a Remotely retrieved Tarball using Tarfile.extractall() |
| 8 | CVE-2022-23522 | High | MindsDB | Arbitrary File Write when Extracting Tarballs using shutil.unpack_archive() |
| 7 | CVE-2023-25803 | High | Roxy-WI | Directory Traversal vulnerability leading to inclusion of server-side files - advisory |
| 6 | CVE-2023-25802 | High | Roxy-WI | Path Traversal via unneutralized dir/../filename sequences - advisory |
| 5 | CVE-2023-25804 | Medium | Roxy-WI | Limited Path Traversal in name parameter |
| N° | CVE | Severity | Target | Description |
|---|---|---|---|---|
| 4 | huntr-309725a2 | Low | scikit-learn | Potential TarSlip (CWE-59 Link Following) when extracting a remote archive without checksum verification - bounty |
| 3 | CVE-2022-23530 | Low | GuardDog (DataDog) | GuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package - advisory |
| 2 | CVE-2022-3607 | Medium | OctoPrint | ZipSlip Symlink variant allows to read any file within OctoPrint Box |
| 1 | CVE-2022-1993 | High | Gogs | Path Traversal vulnerability on the endpoint '/info/refs' - advisory |
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
| Back | FazBrowse Home | New Git URL |