Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.5 CVE-2026-56129

CVE-2026-56129_CVE-2026-56129

Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A l...

Dynabook Inc. Generic IO & Memory Access driver all versions CVE
MEDIUM 4.4 CVE-2026-8330

Insertion of Sensitive Information into Log File in GitLab_CVE-2026-8330

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that unde...

GitLab GitLab 9.3 CVE
MEDIUM 4.3 CVE-2026-5952

Incorrect Authorization in GitLab_CVE-2026-5952

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that un...

GitLab GitLab 17.11 CVE
MEDIUM 4.3 CVE-2026-5796

Incorrect Authorization in GitLab_CVE-2026-5796

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that und...

GitLab GitLab 13.6 CVE
MEDIUM 5.4 CVE-2026-5309

Authorization Bypass Through User-Controlled Key in GitLab_CVE-2026-5309

GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 18.6 CVE
MEDIUM 5.3 CVE-2026-2238

Missing Authorization in GitLab_CVE-2026-2238

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that und...

GitLab GitLab 17.5 CVE
MEDIUM 4.3 CVE-2026-1606

Improper Control of Generation of Code (‘Code Injection’) in GitLab_CVE-2026-1606

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that und...

GitLab GitLab 14.8 CVE
MEDIUM 5.3 CVE-2026-11379

Incorrect Authorization in GitLab_CVE-2026-11379

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in w...

GitLab GitLab 13.11 CVE
MEDIUM 6 CVE-2026-8658

OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin_CVE-2026-8658

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands...

Rapid7 InsightConnect Tcpdump Plugin CVE
MEDIUM 6.5 CVE-2026-2508

Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id'_CVE-2026-2508

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and in...

GravityMore Gravity Bookings CVE