CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
1,295 results Clear all
CVE-2026-2845 6.5 MEDIUM EPSS 0.00
GitLab CE/EE - DoS
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an authenticated user to cause denial of service by exploiting a Bitbucket Server import endpoint via repeatedly sending large responses.
CWE-770 Feb 25, 2026
CVE-2026-1747 4.3 MEDIUM EPSS 0.00
GitLab EE - Privilege Escalation
GitLab has remediated an issue in GitLab EE affecting all versions from 17.11 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that, under certain conditions, could have allowed Developer-role users with insufficient privileges to make unauthorized modifications to protected Conan packages.
CWE-288 Feb 25, 2026
CVE-2026-1725 5.3 MEDIUM EPSS 0.00
GitLab CE/EE 18.9-18.9.1 - DoS
GitLab has remediated an issue in GitLab CE/EE affecting versions from 18.9 before 18.9.1 that could have under certain conditions, allowed an unauthenticated user to cause denial of service by sending specially crafted requests to a CI jobs API endpoint.
CWE-770 Feb 25, 2026
CVE-2026-1662 7.5 HIGH EPSS 0.00
GitLab CE/EE - DoS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.4 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause Denial of Service by sending specially crafted requests to the Jira events endpoint.
CWE-770 Feb 25, 2026
CVE-2026-1388 7.5 HIGH EPSS 0.00
GitLab CE/EE - DoS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause regular expression denial of service by sending specially crafted input to a merge request endpoint under certain conditions.
CWE-1333 Feb 25, 2026
CVE-2026-0752 8.0 HIGH EPSS 0.00
GitLab CE/EE 16.2-18.7.4/18.8-18.8.4/18.9 - XSS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that under certain circumstances, could have allowed an unauthenticated user to inject arbitrary scripts into the Mermaid sandbox UI.
CWE-79 Feb 25, 2026
CVE-2025-14511 7.5 HIGH EPSS 0.00
GitLab CE/EE - DoS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.2 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthenticated user to cause denial of service by sending specially crafted files to the container registry event endpoint under certain conditions.
CWE-1284 Feb 25, 2026
CVE-2025-3525 6.5 MEDIUM EPSS 0.00
GitLab CE/EE - DoS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have, under certain circumstances, allowed an authenticated user with certain access to cause Denial of Service by creating specially crafted CI triggers via the API.
CWE-770 Feb 25, 2026
CVE-2025-14103 4.3 MEDIUM EPSS 0.00
GitLab CE/EE 17.7-18.9 - Privilege Escalation
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.
CWE-862 Feb 25, 2026
CVE-2026-1458 6.5 MEDIUM EPSS 0.00
Gitlab < 18.6.6 - Unrestricted File Upload
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an unauthenticated user to cause denial of service by uploading malicious files.
CWE-434 Feb 11, 2026
CVE-2026-1456 6.5 MEDIUM EPSS 0.00
Gitlab < 18.7.4 - Resource Allocation Without Limits
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through CPU exhaustion by submitting specially crafted markdown files that trigger exponential processing in markdown preview.
CWE-770 Feb 11, 2026
CVE-2026-1387 6.5 MEDIUM EPSS 0.00
Gitlab < 18.6.6 - Resource Allocation Without Limits
GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to cause Denial of Service by uploading a malicious file and repeatedly querying it through GraphQl.
CWE-770 Feb 11, 2026
CVE-2026-1282 3.5 LOW EPSS 0.00
Gitlab < 18.6.6 - Basic XSS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.
CWE-80 Feb 11, 2026
CVE-2026-1094 4.6 MEDIUM EPSS 0.00
GitLab <18.8.4 - Info Disclosure
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 18.8.4 that could have allowed an authenticated developer to hide specially crafted file changes from the WebUI.
CWE-1289 Feb 11, 2026
CVE-2026-1080 4.3 MEDIUM EPSS 0.00
Gitlab < 18.6.6 - IDOR
GitLab has remediated an issue in GitLab EE affecting all versions from 16.7 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to access iteration data from private descendant groups by querying the iterations API endpoint.
CWE-639 Feb 11, 2026
CVE-2026-0958 7.5 HIGH EPSS 0.00
Gitlab < 18.6.6 - Interpretation Conflict
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to cause denial of service through memory or CPU exhaustion by bypassing JSON validation middleware limits.
CWE-436 Feb 11, 2026
CVE-2026-0595 7.3 HIGH EPSS 0.00
Gitlab < 18.6.6 - XSS
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML injection in test case titles.
CWE-79 Feb 11, 2026
CVE-2025-8099 7.5 HIGH EPSS 0.00
Gitlab < 18.6.6 - Resource Allocation Without Limits
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.8 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions, could have allowed an unauthenticated user to cause denial of service by sending repeated GraphQL queries.
CWE-770 Feb 11, 2026
CVE-2025-7659 8.0 HIGH EPSS 0.00
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.
CWE-346 Feb 11, 2026
CVE-2025-14594 3.5 LOW EPSS 0.00
GitLab CE/EE <18.6.6-18.8.4 - Info Disclosure
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.
CWE-639 Feb 11, 2026