Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling. Join the discussion | GCVE Database | 08/21/2026, 09:07:36 UTC Added: 08/17/2026, 22:33:27 UTC |
0 An authorization vulnerability in GitLab CE/EE allows authenticated users with developer role to modify certain package registry metadata without maintainer-level permissions. This issue affects versions from 17.6 up to but not including 19.0.6, 19.1 up to but not including 19.1.4, and 19.2 up to but not including 19.2.2. The flaw was due to improper authorization checks and has been remediated by GitLab. Join the discussion | GCVE Database | 08/18/2026, 10:30:37 UTC Added: 08/12/2026, 20:13:22 UTC |
0 A cross-site scripting (XSS) vulnerability was identified in GitLab CE/EE versions from 19.2 up to but not including 19.2.2. This issue involved improper sanitization of HTML content rendered in a CI job modal, which under certain conditions could allow an authenticated user with developer-role permissions to escalate privileges. The vulnerability has been remediated in version 19.2.2. Join the discussion | GCVE Database | 08/18/2026, 10:28:52 UTC Added: 08/12/2026, 20:13:26 UTC |
0 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a protected branch without the required push permissions due to improper authorization in pipeline reference validation. Join the discussion | GCVE Database | 08/18/2026, 10:28:39 UTC Added: 08/12/2026, 20:13:24 UTC |
Multiple vulnerabilities affecting GitLab Community Edition and Enterprise Edition versions from 12.7 up to but not including 18.10.7, 18.11 up to but not including 18.11.4, and 19.0 up to but not including 19.0.1 have been identified and fixed. These include issues related to improper resource management and authorization flaws across six CVEs including CVE-2026-1402. No known exploits in the wild have been reported. The product is not a cloud service. A patch is available for these vulnerabilities. Join the discussion | GCVE Database | 08/13/2026, 13:19:31 UTC Added: 05/28/2026, 20:54:05 UTC |
A vulnerability in GitLab CE/EE versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow unauthorized users to view project import source information due to a missing authorization check. This issue has been remediated in the specified fixed versions. Join the discussion | GCVE Database | 07/29/2026, 21:31:01 UTC Added: 07/30/2026, 05:46:25 UTC |
A vulnerability in GitLab Enterprise Edition versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 could allow sensitive information disclosure due to improper handling of upstream requests in virtual registries. This issue has been remediated by GitLab in the specified fixed versions. The vulnerability is classified as CWE-522 and has a CVSS 3.1 vector indicating network attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, limited confidentiality impact, no integrity impact, and low availability impact. No known exploits in the wild have been reported. Join the discussion | GCVE Database | 07/29/2026, 21:31:00 UTC Added: 07/30/2026, 05:46:27 UTC |
GitLab Enterprise Edition versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 contain a vulnerability that allows an authenticated user to bypass administrator-configured tool governance policies due to improper authorization enforcement during token generation. This issue affects integrity but does not impact confidentiality or availability. The vulnerability has been remediated in versions 19.1.3 and 19.2.1. No known exploits have been reported in the wild. Join the discussion | GCVE Database | 07/29/2026, 21:31:00 UTC Added: 07/30/2026, 05:46:25 UTC |
Showing 1 to 8 of 8 results