Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26091
Total
1954
Critical
7964
High
8211
Medium
CVE ID Severity Score Description Published
CVE-2026-41566 UNKNOWN Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are recommended to upgrade to version 2.16.0, … Jun 25, 2026
CVE-2026-56129 MEDIUM 5.5 Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user … Jun 25, 2026
CVE-2026-12937 HIGH 7.5 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via the … Jun 25, 2026
CVE-2026-9702 HIGH 7.5 The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination … Jun 25, 2026
CVE-2026-5305 HIGH 8.8 The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to … Jun 25, 2026
CVE-2026-12490 UNKNOWN When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate … Jun 25, 2026
CVE-2026-12246 UNKNOWN NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the … Jun 25, 2026
CVE-2026-12245 UNKNOWN NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be … Jun 25, 2026
CVE-2026-12244 UNKNOWN If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with … Jun 25, 2026
CVE-2026-10824 MEDIUM 6.5 The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthenticated users to read and permanently … Jun 25, 2026
CVE-2026-8330 MEDIUM 4.4 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-5952 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-5796 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-5309 MEDIUM 5.4 GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-3176 LOW 3.1 GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-2238 MEDIUM 5.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-1606 MEDIUM 4.3 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-13311 HIGH 7.5 shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies the entire growing array on every … Jun 25, 2026
CVE-2026-12635 NONE GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-12053 HIGH 8.6 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to … Jun 25, 2026
CVE-2026-11379 MEDIUM 5.3 GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 … Jun 25, 2026
CVE-2026-10712 HIGH 8.0 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-10086 HIGH 8.7 GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-0934 LOW 3.8 GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain … Jun 25, 2026
CVE-2026-2508 MEDIUM 6.5 The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and including, 2.7.1 … Jun 25, 2026