Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.4 CVE-2026-6269

Incorrect Authorization in GitLab_CVE-2026-6269

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that ...

GitLab GitLab 15.10 CVE
MEDIUM 5.1 CVE-2026-53912

Cerebrate self-registration password hash exposure via inbox and audit log views_CVE-2026-53912

Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s h...

cerebrate cerebrate CVE
MEDIUM 5.9 CVE-2026-53423

Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin_CVE-2026-53423

Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-servic...

membraneframework membrane_mp4_plugin 0.3.0 CVE
CRITICAL 9.4 CVE-2026-4764

Privilege Escalation in Dialogflow CX via Playbook Import_CVE-2026-4764

A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user w...

Google Cloud Dialogflow CX CVE
LOW 3.1 CVE-2026-3553

Incorrect Authorization in GitLab_CVE-2026-3553

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that u...

GitLab GitLab 12.0 CVE
MEDIUM 6.5 CVE-2026-1500

Allocation of Resources Without Limits or Throttling in GitLab_CVE-2026-1500

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that ...

GitLab GitLab 17.10 CVE
MEDIUM 4.3 CVE-2026-10733

Improper Restriction of Rendered UI Layers or Frames in GitLab_CVE-2026-10733

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that c...

GitLab GitLab 17.0 CVE
HIGH 8.7 CVE-2026-10087

Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) in GitLab_CVE-2026-10087

GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that unde...

GitLab GitLab 17.1, 18.11, 19.0 CVE
CRITICAL 9.8 CVE-2026-7852

Unrestricted File Upload in Limatek’s LimRAD NAC_CVE-2026-7852

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects L...

Limatek System Inc. LimRAD NAC before 5.5.7.3.9 CVE
MEDIUM 5.3 CVE-2026-49214

guzzlehttp/psr7 has CRLF Injection via URI Host Component_CVE-2026-49214

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace...

guzzle psr7 < 2.10.2 CVE