CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
GitLab GitLab
Real-time zero-day and critical vulnerability monitoring with comprehensive statistics
0
15
0
Last 30 days from trusted security sources
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
GitLab GitLab
Dell RecoverPoint for Virtual Machines (RP4VMs) contains an use of hard-coded credentials vulnerability that could allow an unauthenticated remote att...
Dell RecoverPoint for Virtual Machines (RP4VMs)
Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery vulnerability if WebEx zimlet installed and zimlet JSP is enabled.
Synacor Zimbra Collaboration Suite
TeamT5 ThreatSonar Anti-Ransomware contains an unrestricted upload of file with dangerous type vulnerability. ThreatSonar Anti-Ransomware does not pro...
TeamT5 ThreatSonar Anti-Ransomware
Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a ...
Microsoft Windows
Google Chromium CSS contains a use-after-free vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HT...
Google Chromium
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow a...
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)
Apple iOS, macOS, tvOS, watchOS, and visionOS contain an improper restriction of operations within the bounds of a memory buffer vulnerability that co...
Apple Multiple Products
Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending speci...
Microsoft Configuration Manager
Notepad++ when using the WinGUp updater, contains a download of code without integrity check vulnerability that could allow an attacker to intercept o...
Notepad++ Notepad++
SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restr...
SolarWinds Web Help Desk
Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security featur...
Microsoft Windows
Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service local...
Microsoft Windows
Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature o...
Microsoft Windows
Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate p...
Microsoft Windows
CISA KEV: Known Exploited Vulnerabilities from CISA - actively being exploited in the wild and requiring immediate remediation
NVD Recent: Recently published high/critical severity CVEs from the National Vulnerability Database with CVSS v3.1 scoring
Update Frequency: Data is cached for 30 minutes and refreshed automatically to ensure timely security intelligence
Sources: CISA KEV Catalog, NVD API