CVE & Exploit Intelligence Database

Updated 2h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
3 results Clear all
CVE-2022-2251 4.8 MEDIUM EPSS 0.02
Gitlab Runner < 15.3.5 - OS Command Injection
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger a pipeline to execute commands in the runner as that other user.
CWE-78 Jan 17, 2023
CVE-2020-13327 6.0 MEDIUM EPSS 0.00
GitLab Runner <13.4.2-<13.3.7-<13.2.10 - Info Disclosure
An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments
Oct 22, 2020
CVE-2020-13295 5.4 MEDIUM 1 Writeup EPSS 0.00
GitLab Runner <13.0.12-13.2.3 - SSRF
For GitLab Runner before 13.0.12, 13.1.6, 13.2.3, by replacing dockerd with a malicious server, the Shared Runner is susceptible to SSRF.
CWE-918 Aug 10, 2020