Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56907
Total
4512
Critical
16897
High
16715
Medium
CVE ID Severity Score Description Published
CVE-2026-7514 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated … Sep 16, 2026
CVE-2026-79708 HIGH 8.5 GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain … Sep 16, 2026
CVE-2026-78252 HIGH 8.2 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain … Sep 16, 2026
CVE-2026-73447 CRITICAL 9.1 A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC … Sep 16, 2026
CVE-2026-3855 LOW 3.1 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 16, 2026
CVE-2026-1168 HIGH 7.5 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 16, 2026
CVE-2026-19857 MEDIUM 4.8 The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token … Sep 16, 2026
CVE-2026-19619 MEDIUM 4.7 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 16, 2026
CVE-2026-19248 UNKNOWN — QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input. Sep 16, 2026
CVE-2026-16794 MEDIUM 4.3 GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 16, 2026
CVE-2026-13407 MEDIUM 5.4 The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the … Sep 16, 2026
CVE-2025-14871 HIGH 7.5 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 16, 2026
CVE-2024-11222 MEDIUM 6.4 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain … Sep 16, 2026
CVE-2026-92358 MEDIUM 6.4 A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary … Sep 16, 2026
CVE-2026-89328 UNKNOWN — The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board membership. … Sep 16, 2026
CVE-2026-89327 UNKNOWN — The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing … Sep 16, 2026
CVE-2026-88910 UNKNOWN — The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media … Sep 16, 2026
CVE-2026-87959 UNKNOWN — The WPBot WordPress plugin before 8.7.6 does not perform a capability check on the AJAX action that saves its Claude AI provider settings, allowing users … Sep 16, 2026
CVE-2026-87907 UNKNOWN — The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoints that return booking service and category records, allowing … Sep 16, 2026
CVE-2026-87896 UNKNOWN — The Rox Appointment Booking WordPress plugin before 1.2.8 does not perform any authorization check on the endpoint that returns booking agent (staff) records, allowing unauthenticated … Sep 16, 2026
CVE-2026-87860 UNKNOWN — The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not verify the security token on the request that cancels a subscription, allowing attackers to make … Sep 16, 2026
CVE-2026-87854 UNKNOWN — The Subscriptions for WooCommerce WordPress plugin before 2.0.3 does not correctly validate the shared secret protecting one of its REST endpoints, allowing unauthenticated users to … Sep 16, 2026
CVE-2026-87828 UNKNOWN — The Seraphinite Accelerator WordPress plugin before 2.29.24 does not perform a capability check on one of its state-update AJAX actions, allowing authenticated users such as … Sep 16, 2026
CVE-2026-86823 UNKNOWN — The Newsletter WordPress plugin before 9.3.7 does not validate the destination of the redirect performed after a public subscription action, allowing unauthenticated attackers to redirect … Sep 16, 2026
CVE-2026-86784 UNKNOWN — The Visualizer WordPress plugin before 4.0.8 does not sanitise and escape a chart's JSON data source configuration before outputting it back in the chart editor, … Sep 16, 2026