Total CVEs

140,303

Critical Severity

3,711

High Severity

13,344

Last 7 Days

1,811
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 841 - 860 of 36,708 CVEs
CVE-2026-10824 MEDIUM - 6.5

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently delete any user's course-progress records.

Vendor: Unknown
Product: Masteriyo LMS
Published: Jun 25, 2026
Source: NVD
CVE-2026-8330 MEDIUM - 4.4

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a CI/CD API endpoint.

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-5952 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules and overwrite protecte...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-5796 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from projects with the Pack...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-5309 MEDIUM - 5.4

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy settings without autho...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-3176 LOW - 3.1

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to insufficient authorization chec...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-2238 MEDIUM - 5.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to improper authorization c...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-1606 MEDIUM - 4.3

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-13311 HIGH - 7.5

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every iteration. As a result parse() runs in O(n^2) time relative to the number of input tokens. An attacker who can supply an ...

Vendor: ljharb
Product: shell-quote
Published: Jun 25, 2026
Source: NVD

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network resources through mir...

Vendor: GitLab
Product: GitLab
Published: Jun 25, 2026
Source: NVD
CVE-2026-12053 HIGH - 8.6

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

Vendor: GitLab
Product: GitLab
Published: Jun 25, 2026
Source: NVD
CVE-2026-11379 MEDIUM - 5.3

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile secrets under certain...

Vendor: GitLab
Product: GitLab
Published: Jun 25, 2026
Source: NVD
CVE-2026-10712 HIGH - 8.0

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path v...

Vendor: GitLab
Product: GitLab
Published: Jun 25, 2026
Source: NVD
CVE-2026-10086 HIGH - 8.7

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in the context of anoth...

Vendor: GitLab
Product: GitLab
Published: Jun 25, 2026
Source: NVD
CVE-2026-0934 LOW - 3.8

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected environment configurations ...

Vendor: gitlab
Product: gitlab
Published: Jun 25, 2026
Source: NVD
CVE-2026-2508 MEDIUM - 6.5

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜staff_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

Published: Jun 25, 2026
Source: NVD
CVE-2026-12079 MEDIUM - 6.5

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...

Vendor: wedevs
Product: Dokan Pro
Published: Jun 25, 2026
Source: NVD
CVE-2026-12077 HIGH - 7.5

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin...

Vendor: wedevs
Product: Dokan Pro
Published: Jun 25, 2026
Source: NVD
CVE-2026-10833 MEDIUM - 6.4

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configurablePrefix' Block Attribute in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output esc...

Vendor: wpdevteam
Product: Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns
Published: Jun 25, 2026
Source: NVD
CVE-2026-8662 LOW - 3.3

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.

Published: Jun 25, 2026
Source: NVD