CVE Vulnerability Database
Search and browse 397,974 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4527 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2026-4524 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.9.1 before 18.9.7, 18.10 before 18.10.6, a... |
| CVE-2026-3829 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v... |
| CVE-2026-3607 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-3160 | MEDIUM | 5.8 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-3074 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-3073 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-2900 | LOW | 2.7 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 16.10 before 18.9.7, 18.10 before 18.10.6, and 1... |
| CVE-2026-1659 | HIGH | 7.5 | 0.4% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.0 before 18.9.7, 18.10 before 18.10.6, and ... |
| CVE-2026-1338 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2026-1322 | HIGH | 8.1 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2026-1184 | HIGH | 7.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.9 before 18.9.7, 18.10 before 18.10.6, and 18... |
| CVE-2025-15345 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | The MapGeo – Interactive Geo Maps plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'map' par... |
| CVE-2025-14870 | HIGH | 7.5 | 0.3% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-14869 | HIGH | 7.5 | 0.4% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-13874 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and... |
| CVE-2025-12669 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.9.7, 18.10 before 18.10.6, an... |
| CVE-2026-7648 | MEDIUM | 4.3 | 0.4% | May 14, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to payment b... |
| CVE-2026-7525 | MEDIUM | 4.3 | 0.3% | May 14, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to authorization bypass in all versions up... |
| CVE-2026-5361 | MEDIUM | 6.4 | 0.4% | May 14, 2026 | The Envira Gallery Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API in versions u... |
| CVE-2026-5486 | MEDIUM | 6.5 | 0.5% | May 14, 2026 | The Unlimited Elements for Elementor plugin for WordPress is vulnerable to SQL Injection via the 'data[filter_search]' p... |
| CVE-2026-46446 | HIGH | 7.1 | 0.2% | May 14, 2026 | SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext passwords are stored, allows SQL injection. This i... |
| CVE-2026-46445 | HIGH | 7.1 | 0.2% | May 14, 2026 | SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection. |
| CVE-2026-46419 | HIGH | 7.5 | 0.3% | May 14, 2026 | Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value i... |
| CVE-2026-44919 | MEDIUM | 6.5 | 0.5% | May 14, 2026 | In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc... |
