CVE-2021-22175: GitLab Server-Side Request Forgery (SSRF) Vulnerability
CVE-2021-22175 affects GitLab GitLab and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-18.
Deep dives, practical guides, and incident analyses from engineers who build Safeguard. No fluff, no vendor FUD — just what you need to ship secure software.
CVE-2021-22175 affects GitLab GitLab and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-18.
CVE-2025-68461 affects Roundcube Webmail and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-20.
CVE-2025-49113 affects Roundcube Webmail and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-20.
CVE-2026-25108 affects Soliton Systems K.K FileZen and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-24.
CVE-2026-20127 affects Cisco Catalyst SD-WAN Controller and Manager and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-25.
CVE-2022-20775 affects Cisco SD-WAN and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-25.
CVE-2026-21385 affects Qualcomm Multiple Chipsets and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-03.
CVE-2026-22719 affects Broadcom VMware Aria Operations and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-03.
CVE-2023-41974 affects Apple iOS and iPadOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-03-05.
Weekly insights on software supply chain security, delivered to your inbox.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.