CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-39935MEDIUM | GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) VulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API CWE-918Dec 13, 2021 | CVSS6.8v3.1 | EPSS35.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-22205CRITICAL | GitLab Community and Enterprise Editions Remote Code Execution VulnerabilityAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. | CVSS10.0v3.1 | EPSS99.7% | PoCs34 | SignalsListed in CISA KEVKnown ransomware use2 Nuclei templates | STIX |