Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2026-13311

shell-quote parse() is quadratic in token count, enabling denial of service_CVE-2026-13311

shell-quote prior to 1.8.5 finalizes parsed tokens in parse() using Array.prototype.concat as a reduce accumulator, which reallocates and copies th...

ljharb shell-quote CVE
HIGH 8.6 CVE-2026-12053

Insertion of Sensitive Information into Log File in GitLab_CVE-2026-12053

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user ...

GitLab GitLab 19.1 CVE
MEDIUM 5.3 CVE-2026-11379

Incorrect Authorization in GitLab_CVE-2026-11379

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in w...

GitLab GitLab 13.11 CVE
HIGH 8 CVE-2026-10712

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in GitLab_CVE-2026-10712

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that un...

GitLab GitLab 18.10 CVE
HIGH 8.7 CVE-2026-10086

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in GitLab_CVE-2026-10086

GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 16.4 CVE
LOW 3.8 CVE-2026-0934

Incorrect Authorization in GitLab_CVE-2026-0934

GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under ...

GitLab GitLab 17.9 CVE
NONE 80E15B48-9525-

cerberus-redteam_80E15B48-9525-5CE1-8DB6-0FC4C91F9811

Agent Autonome de Red Teaming Guidé par LLM et MITRE ATT&CK Projet Fil Rouge — Périmètre 2 : Red Teaming & LLM Télécom Paris — MSCYBER2 BE4 --- Dém...

N/A N/A GITHUBEXPLOIT
NONE 462F4346-7AE4-

Secure-Authentication-Demo_462F4346-7AE4-5690-8B80-B98FAD7207FA

No description provided...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 05A924D8-6752-

APACHE-2.4.49-2.4.50-exploit_05A924D8-6752-5085-A17B-85A9635984FD

CVE-2021-42013-PoC A lightweight, interactive Bash utility designed to audit and verify vulnerability to CVE-2021-42013 Apache HTTP Server 2.4.49 /...

N/A N/A GITHUBEXPLOIT
LOW 3.3 CVE-2026-8662

Path Traversal in Rapid7 InsightConnect Compression Plugin_CVE-2026-8662

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to ...

Rapid7 InsightConnect Compression Plugin CVE