Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-1184 — Deserialization of Untrusted Data in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause den…

gitlab | Remote | Denial of Service
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.1 MEDIUM
CVE-2025-15345 — MapGeo - Interactive Geo Maps <= 1.6.27 - Reflected Cross-Site Scripting via 'map' Parame…

The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' parameter in the display-map shortcode in all versions up to, and including, 1.6.2…

interactive_geo_maps | Remote | Cross-Site Scripting
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.5 HIGH
CVE-2025-14870 — Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause …

gitlab | Remote | Denial of Service
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
7.5 HIGH
CVE-2025-14869 — Improper Validation of Specified Quantity in Input in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an unauthenticated user to cause …

gitlab | Remote | Denial of Service
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
4.3 MEDIUM
CVE-2025-13874 — Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with Guest …

gitlab | Remote | Authorization
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
5.4 MEDIUM
CVE-2025-12669 — Improper Control of Generation of Code ('Code Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to inject …

gitlab | Remote | Cross-Site Scripting
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
4.3 MEDIUM
CVE-2026-7648 — LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.3.5 - Authentic…

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment bypass through user-controlled key in all versions up to, and including, 4.3.5. …

learnpress | Remote | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-7525 — My Calendar <= 3.7.9 - Authenticated (Custom+) Missing Authorization to Unauthorized Even…

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.7.9. This is due to the plugin not properly verifying tha…

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.4 MEDIUM
CVE-2026-5361 — Envira Gallery <= 1.12.4 - Authenticated (Author+) Stored Cross-Site Scripting via 'arrow…

The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions up to and including 1.12.4. This is due to insufficient input sanitization in th…

envira_gallery | Remote | Cross-Site Scripting
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-5486 — Unlimited Elements For Elementor <= 2.0.7 - Authenticated (Contributor+) SQL Injection vi…

The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' parameter in the get_cat_addons AJAX action in versions up to and including 2.0.…

unlimited_elements_for_elementor | Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.1 HIGH
CVE-2026-46446 — SOGo PostgreSQL/MariaDB SQL Injection

SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This is related to c_password = '%@' in changePasswordForLogin.

sogo | Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.1 HIGH
CVE-2026-46445 — SOGo PostgreSQL SQL Injection Vulnerability

SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.

sogo | Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.5 HIGH
CVE-2026-46419 — Yubico Webauthn-Server Core Java Webauthn Impersonation Vulnerability

Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.

Remote | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-44919 — OpenStack Ironic Infinite Loop File Protocol Checksum Vulnerability

In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///dev/zero URL.

ironic | Remote | Denial of Service
May 14, 2026 May 20, 2026
May 14, 2026
May 20, 2026
6.3 MEDIUM
CVE-2026-41281 — KDDI CORPORATION Android App "あんしんフィルター for au" Cleartext Transmission of Sensitive Infor…

Android App "あんしんフィルター for au" provided by KDDI CORPORATION contains Cleartext Transmission of Sensitive Information (CWE-319) vulnerability. A man-in-the-middle attacker may access and modify commun…

| Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.8 CRITICAL
CVE-2026-8500 — Web::Passwd versions through 0.03 for Perl is vulnerable to RCE

Web::Passwd versions through 0.03 for Perl is vulnerable to RCE. Web::Passwd is a small CGI application for managing htpasswd files using the htpasswd command. The user parameter is not validated o…

Remote | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.1 HIGH
CVE-2026-32991 — Apache Team Privilege Escalation Vulnerability

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

Remote | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
8.1 HIGH
CVE-2026-29206 — Apache sqloptimizer SQL Injection Vulnerability

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

Remote | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-45158 — OPNsense: Command Injection via Attacker-Controlled DHCP Config

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell scrip…

opnsense | Remote | Injection
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
7.5 HIGH
CVE-2026-44478 — hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingComplete…

hoppscotch | Remote | Information Disclosure
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
Showing 20 of 7188 Results