CVEs affecting projects tracked on Release Alert, from NVD & OSV.
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.