git Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for git products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
13
In CISA KEV
5
Beyond CISA KEV
8
Sensor Observed
0
Virtual Patch Available
0
git KEVs Added by Year
13 git KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2023-26802
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass... |
DCBI-Netlog-LAB | High | Not in CISA | 07 Jul 2025 |
|
CVE-2023-23489
The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's'... |
WordPress Plugin | High | Not in CISA | 07 Jul 2025 |
|
CVE-2016-10108
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified... |
MyCloud NAS | High | Not in CISA | 05 Jul 2025 |
|
CVE-2021-22175
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions... |
GitLab | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2021-39935
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before... |
GitLab | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-48384
Git allows arbitrary code execution through broken config quoting |
git | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2018-25126
TVT NVMS-9000 Hard-coded API Credentials & Command Injection |
NVMS-9000 | High | Not in CISA | 24 Nov 2025 |
|
CVE-2021-4191
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with... |
GitLab | High | Not in CISA | 28 Apr 2025 |
|
CVE-2021-22205
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were... |
GitLab | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2023-7028
Weak Password Recovery Mechanism for Forgotten Password in GitLab |
GitLab | Confirmed | In CISA | 01 May 2024 |
|
CVE-2022-34538
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component... |
DW MEGApix IP cameras | High | Not in CISA | 19 Jul 2022 |
|
CVE-2021-22214
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions... |
GitLab | High | Not in CISA | 08 Jun 2021 |
|
CVE-2017-17560
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component,... |
MyCloud PR4100 | High | Not in CISA | 12 Dec 2017 |
Common Vulnerability Classes (CWE)
- CWE-918 — Server-Side Request Forgery (SSRF) 3
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
- CWE-436 — Interpretation Conflict 1
- CWE-59 — Improper Link Resolution Before File Access ('Link Following') 1
- CWE-640 — Weak Password Recovery Mechanism for Forgotten Password 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-798 — Use of Hard-coded Credentials 1
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology