VulnScope — package-centric CVE lookup- MEDIUM5.4CVE-2026-6269Incorrect Authorization in GitLab
- LOW3.1CVE-2026-3553Incorrect Authorization in GitLab
- MEDIUM6.5Allocation of Resources Without Limits or Throttling in GitLab
- MEDIUM4.3Improper Restriction of Rendered UI Layers or Frames in GitLab
- HIGH8.7Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
- HIGH7.5File Browser has incorrect access control for public directory shares via rule path rebasing
- MEDIUM6.8File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
- MEDIUM6.5File Browser has a DoS Vulnerability via Public Login API
- MEDIUM6.9Netty is a network application framework for development of protocol servers and clients.
- HIGH7.5Netty is a network application framework for development of protocol servers and clients.
- HIGH7.5Netty is a network application framework for development of protocol servers and clients.
- HIGH7.5Netty is a network application framework for development of protocol servers and clients.
- MEDIUM4.8Netty is a network application framework for development of protocol servers and clients.
- MEDIUM5.3Netty is a network application framework for development of protocol servers and clients.
- MEDIUM6.7A flaw was found in QEMU's virtio-blk device.
- MEDIUM5.3OpenTelemetry-cpp is the C++ implementation of OpenTelemetry.
- MEDIUM6.5Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint
- MEDIUM6.5Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint
- MEDIUM5.4Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
- MEDIUM5.3Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations.
- MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks.
- HIGH7.5Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts.
- HIGH7.7Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs)
- LOW3.7Tornado has out-of-bounds memory access via C extension
- MEDIUM5.9gorest InMemorySecret2FA race condition allows process crash via concurrent map access (CWE-362)