Vulnerabilities
Vulnerable Software
Security Vulnerabilities
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to perform actions beyond the intended scope of that token due to improper authorization checks.
CVSS Score
5.4
EPSS Score
0.001
Published
2026-09-24
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
CVSS Score
9.9
EPSS Score
0.005
Published
2026-09-24
Microsoft Office Outlook Remote Code Execution Vulnerability
CVSS Score
8.8
EPSS Score
0.004
Published
2026-09-23
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-09-23
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended for other users or environments.
CVSS Score
7.7
EPSS Score
0.002
Published
2026-09-23
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.
CVSS Score
7.7
EPSS Score
0.003
Published
2026-09-23
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.
CVSS Score
8.8
EPSS Score
0.01
Published
2026-09-23
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.
CVSS Score
8.8
EPSS Score
0.006
Published
2026-09-23
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS Score
8.8
EPSS Score
0.01
Published
2026-09-23
IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
CVSS Score
9.8
EPSS Score
0.003
Published
2026-09-23


Contact Us

Shodan ® - All rights reserved