CVEs affecting projects tracked on Release Alert, from NVD & OSV.
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission