Vulnerabilities
Summary — last 7 days
New vulnerabilities2,833▲ 195 vs. last week
Critical / high1,316▼ 117 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)237▲ 223 vs. last week
7 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Critical (9.8) | 1.8% | — | Gitolite | 11/7/2019 | 6/16/2026 | gitolite before 1.4.1 does not filter src/ or hooks/ from path names. | |
| Modified | High (8.1) | 2.0% | — | Gitolite | 1/10/2019 | 6/17/2026 | commands/rsync in Gitolite before 3.6.11, if .gitolite.rc enables rsync, mishandles the rsync command line, which allows attackers to have a "bad" impact by triggering use of an option other than -v, -n, -q, or -P. | |
| Modified | Medium (5.5) | 0.42% | — | Gitolite | 9/21/2018 | 6/17/2026 | gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup. | |
| Modified | Critical (9.8) | 3.1% | — | Gitolite | 9/21/2018 | 6/16/2026 | gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs. | |
| Modified | High (8.1) | 1.2% | — | Gitolite | 9/12/2018 | 6/17/2026 | Gitolite before 3.6.9 does not (in certain configurations involving @all or a regex) properly restrict access to a Git repository that is in the process of being migrated until the full set of migration steps has been completed. This can allow valid users to obtain unintended access. | |
| Modified | Medium (4.6) | 2.1% | — | GitoliteSitaram Chamarty Gitolite | 10/22/2012 | 6/16/2026 | Directory traversal vulnerability in gitolite 3.x before 3.1, when wild card repositories and a pattern matching "../" are enabled, allows remote authenticated users to create arbitrary repositories and possibly perform other actions via a .. (dot dot) in a repository name. | |
| Modified | Medium (6.8) | 2.9% | — | Gitolite | 10/4/2011 | 6/16/2026 | Directory traversal vulnerability in the Admin Defined Commands (ADC) feature in gitolite before 1.5.9.1 allows remote attackers to execute arbitrary commands via .. (dot dot) sequences in admin-defined commands. |