—CVE-2026-11527Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument i…
MEDIUM6.8CVE-2026-54421In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can retu…
—
—
—
—
—
—
MEDIUM6.3Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in ninenines cowlib allows HTTP…
—
—
—
—
—
—
—
—
—
MEDIUM5.4Incorrect Authorization in GitLab
LOW3.1Incorrect Authorization in GitLab
MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitLab
MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames in GitLab
HIGH8.7Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
—Sensitive data could be written to mongod.log
—File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection