git vendor intelligence

git Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting git products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse git KEVs Full KEV feed
Total KEVs
14
Known exploited vulnerabilities affecting git products
In CISA KEV
5
Records also listed in the official catalog
Beyond CISA KEV
9
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
git KEV with sensor-observed exploitation activity

The catalog gap matters for git exposure

Nine of the fourteen exploited git CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 64% of this vendor portfolio.

36%
Covered by CISA
64%
Beyond CISA
8
Product families

Attested git CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2023-2825

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal...

GitLab Confirmed Beyond CISA 03 Aug 2026
CVE-2023-26802

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass...

DCBI-Netlog-LAB High Beyond CISA 07 Jul 2025
CVE-2023-23489

The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's'...

WordPress Plugin High Beyond CISA 07 Jul 2025
CVE-2016-10108

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified...

MyCloud NAS High Beyond CISA 05 Jul 2025
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions...

GitLab Confirmed In CISA 01 Jun 2026
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before...

GitLab Confirmed In CISA 01 Jun 2026
CVE-2025-48384

Git allows arbitrary code execution through broken config quoting

git Confirmed In CISA 01 Jun 2026
CVE-2018-25126

TVT NVMS-9000 Hard-coded API Credentials & Command Injection

NVMS-9000 High Beyond CISA 24 Nov 2025
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with...

GitLab High Beyond CISA 28 Apr 2025
CVE-2021-22205

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were...

GitLab Confirmed In CISA 03 Nov 2021
CVE-2023-7028

Weak Password Recovery Mechanism for Forgotten Password in GitLab

GitLab Confirmed In CISA 01 May 2024
CVE-2022-34538

Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component...

DW MEGApix IP cameras High Beyond CISA 19 Jul 2022
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions...

GitLab High Beyond CISA 08 Jun 2021
CVE-2017-17560

An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component,...

MyCloud PR4100 High Beyond CISA 12 Dec 2017

Showing 14 of 14 git known exploited vulnerabilities.

Recurring weakness patterns

Server-side request forgery (ssrf), neutralization, and limitation account for seven mapped occurrences across this git KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.