git Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for git products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

13

In CISA KEV

5

Beyond CISA KEV

8

Sensor Observed

0

Virtual Patch Available

0

git KEVs Added by Year

Loading...

13 git KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2023-26802

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass...

High Not in CISA 07 Jul 2025
CVE-2023-23489

The Easy Digital Downloads WordPress Plugin, versions 3.1.0.2 & 3.1.0.3, is affected by an unauthenticated SQL injection vulnerability in the 's'...

High Not in CISA 07 Jul 2025
CVE-2016-10108

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytics.php URL via a modified...

High Not in CISA 05 Jul 2025
CVE-2021-22175

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions...

Confirmed In CISA 01 Jun 2026
CVE-2021-39935

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before...

Confirmed In CISA 01 Jun 2026
CVE-2025-48384

Git allows arbitrary code execution through broken config quoting

Confirmed In CISA 01 Jun 2026
CVE-2018-25126

TVT NVMS-9000 Hard-coded API Credentials & Command Injection

High Not in CISA 24 Nov 2025
CVE-2021-4191

An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Private GitLab instances with...

High Not in CISA 28 Apr 2025
CVE-2021-22205

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were...

Confirmed In CISA 03 Nov 2021
CVE-2023-7028

Weak Password Recovery Mechanism for Forgotten Password in GitLab

Confirmed In CISA 01 May 2024
CVE-2022-34538

Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component...

High Not in CISA 19 Jul 2022
CVE-2021-22214

When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions...

High Not in CISA 08 Jun 2021
CVE-2017-17560

An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component,...

High Not in CISA 12 Dec 2017

Common Vulnerability Classes (CWE)

  • CWE-918 — Server-Side Request Forgery (SSRF) 3
  • CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 2
  • CWE-436 — Interpretation Conflict 1
  • CWE-59 — Improper Link Resolution Before File Access ('Link Following') 1
  • CWE-640 — Weak Password Recovery Mechanism for Forgotten Password 1
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
  • CWE-798 — Use of Hard-coded Credentials 1
  • CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology