Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56907
Total
4512
Critical
16897
High
16715
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-7514 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated … | Sep 16, 2026 |
| CVE-2026-79708 | HIGH | 8.5 | GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain … | Sep 16, 2026 |
| CVE-2026-78252 | HIGH | 8.2 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain … | Sep 16, 2026 |
| CVE-2026-73447 | CRITICAL | 9.1 | A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC … | Sep 16, 2026 |
| CVE-2026-3855 | LOW | 3.1 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2026-1168 | HIGH | 7.5 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2026-19857 | MEDIUM | 4.8 | The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token … | Sep 16, 2026 |
| CVE-2026-19619 | MEDIUM | 4.7 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2026-19248 | UNKNOWN | — | QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input. | Sep 16, 2026 |
| CVE-2026-16794 | MEDIUM | 4.3 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2026-13407 | MEDIUM | 5.4 | The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the … | Sep 16, 2026 |
| CVE-2025-14871 | HIGH | 7.5 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2024-11222 | MEDIUM | 6.4 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … | Sep 16, 2026 |
| CVE-2026-92358 | MEDIUM | 6.4 | A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary … | Sep 16, 2026 |
| CVE-2026-89328 | UNKNOWN | — | The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. … | Sep 16, 2026 |
| CVE-2026-89327 | UNKNOWN | — | The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing … | Sep 16, 2026 |
| CVE-2026-88910 | UNKNOWN | — | The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media … | Sep 16, 2026 |
| CVE-2026-87959 | UNKNOWN | — | The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users … | Sep 16, 2026 |
| CVE-2026-87907 | UNKNOWN | — | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing … | Sep 16, 2026 |
| CVE-2026-87896 | UNKNOWN | — | The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated … | Sep 16, 2026 |
| CVE-2026-87860 | UNKNOWN | — | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make … | Sep 16, 2026 |
| CVE-2026-87854 | UNKNOWN | — | The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to … | Sep 16, 2026 |
| CVE-2026-87828 | UNKNOWN | — | The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as … | Sep 16, 2026 |
| CVE-2026-86823 | UNKNOWN | — | The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect … | Sep 16, 2026 |
| CVE-2026-86784 | UNKNOWN | — | The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, … | Sep 16, 2026 |