Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-11379

Incorrect Authorization in GitLab_CVE-2026-11379

GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in w...

GitLab GitLab 13.11 CVE
MEDIUM 6 CVE-2026-8658

OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin_CVE-2026-8658

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands...

Rapid7 InsightConnect Tcpdump Plugin CVE
MEDIUM 6.5 CVE-2026-2508

Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id'_CVE-2026-2508

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and in...

GravityMore Gravity Bookings CVE
MEDIUM 6.5 CVE-2026-12079

Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter_CVE-2026-12079

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0....

wedevs Dokan Pro CVE
MEDIUM 6.4 CVE-2026-10833

Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute_CVE-2026-10833

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...

wpdevteam Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns CVE
MEDIUM 6 CVE-2026-8663

OS Command Injection in Rapid7 InsightConnect RPM Plugin_CVE-2026-8663

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via...

Rapid7 InsightConnect RPM Plugin CVE
MEDIUM 6 CVE-2026-8659

OS Command Injection in Rapid7 InsightConnect SQLmap Plugin_CVE-2026-8659

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands ...

Rapid7 InsightConnect SQLmap Plugin CVE
MEDIUM 6.5 CVE-2026-9153

Arbitrary File Read in Rapid7 InsightConnect Sed Plugin_CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expre...

Rapid7 InsightConnect Sed Plugin CVE
MEDIUM 6 CVE-2026-8664

OS Command Injection in Rapid7 InsightConnect Finger Plugin_CVE-2026-8664

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands ...

Rapid7 InsightConnect Finger Plugin CVE
MEDIUM 5.1 CVE-2026-49979

Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter_CVE-2026-49979

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accept...

appsmithorg appsmith < 1.99 CVE