Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-8030 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authentic…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-86475 — Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-App…

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitor…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.3 MEDIUM
CVE-2026-84906 — Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Trans…

The Eventin WordPress plugin before 4.1.24 does not verify that a completed payment corresponds to the order it is applied to, confirming only that the payment gateway reports the transaction as succ…

Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.3 MEDIUM
CVE-2026-7514 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that an authenticated user with developer-role permissions co…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.5 HIGH
CVE-2026-79708 — Incorrect Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticat…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
8.2 HIGH
CVE-2026-78252 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in G…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could h…

Remote | Cross-Site Request Forgery
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
9.4 CRITICAL
CVE-2026-73447 — Security Advisory 0162 - gNSI Certz/Bootz OS Command Injection via Crafted Rotate Request

A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full device compromise. An authenticated user can exploit gRPC Network Security Inte…

eos | Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
3.1 LOW
CVE-2026-3855 — Improper Control of Resource Identifiers ('Resource Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authent…

Remote | Path Traversal
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2026-1168 — Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthe…

Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.8 MEDIUM
CVE-2026-19857 — Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] C…

The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML…

Remote | Injection
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.7 MEDIUM
CVE-2026-19619 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in G…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthent…

Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.1 HIGH
CVE-2026-19248 — Unbounded recursion vulnerability in the QDomNode destructor of Qt XML impacts Qt

QDomDocument XML parsing is vulnerable to a remotely-triggerable denial-of-service crash when processing untrusted input.

Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
4.3 MEDIUM
CVE-2026-16794 — Missing Authorization in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 18.11 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an authenticat…

Remote | Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
5.4 MEDIUM
CVE-2026-13407 — Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notific…

The Royal Elementor Addons WordPress plugin before 1.7.1067 does not properly sanitize and escape values submitted through its form widget before including them in the body of administrator notificat…

Remote | Cross-Site Scripting
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
7.5 HIGH
CVE-2025-14871 — Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthe…

Remote | Denial of Service
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.4 MEDIUM
CVE-2024-11222 — Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer …

Remote | Race Condition
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
6.4 MEDIUM
CVE-2026-92358 — Keycloak-services: keycloak-services: residual cross-browser account-link proof allows si…

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this…

single_sign-on build_of_keycloak | Remote | Authentication
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-89328 — FluentBoards < 2.0.15 - Board Member+ Board Membership and Public Access Modification

The FluentBoards WordPress plugin before 2.0.15 does not properly verify that a user holds board-manager privileges before performing several board-management operations, checking only board members…

| Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-89327 — FluentBoards < 2.0.15 - Board Member+ Comment Author Spoofing via 'comment_by' Parameter

The FluentBoards WordPress plugin before 2.0.15 does not verify that a board member submitting a comment is the user the comment is attributed to, allowing any board member to post comments that app…

| Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
0.0 NA
CVE-2026-88910 — KBoard < 6.7 - Unauthenticated Board Media Deletion via IDOR

The kboard WordPress plugin before 6.7 does not verify ownership or context before deleting board media, allowing unauthenticated attackers to permanently delete its uploaded media files and their da…

| Authorization
Sep 16, 2026 Sep 16, 2026
Sep 16, 2026
Sep 16, 2026
Showing 20 of 14401 Results