| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5952 | Incorrect Authorization in GitLab | GitLab | GitLab | Medium | 4.3 | 2026-06-25 04:34:14 | Deep Dive |
| CVE-2026-8330 | Insertion of Sensitive Information into Log File in GitLab | GitLab | GitLab | Medium | 4.4 | 2026-06-25 04:34:04 | Deep Dive |
| CVE-2026-10712 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab | GitLab | GitLab | High | 8.0 | 2026-06-25 04:33:54 | Deep Dive |
| CVE-2026-11379 | Incorrect Authorization in GitLab | GitLab | GitLab | Medium | 5.3 | 2026-06-25 04:33:49 | Deep Dive |
| CVE-2026-12053 | Insertion of Sensitive Information into Log File in GitLab | GitLab | GitLab | High | 8.6 | 2026-06-25 04:33:44 | Deep Dive |
| CVE-2026-12635 | Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab | GitLab | GitLab | None | 0.0 | 2026-06-25 04:33:34 | Deep Dive |
| CVE-2026-2508 | Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id' | GravityMore | Gravity Bookings | Medium | 6.5 | 2026-06-25 03:42:22 | Deep Dive |
| CVE-2026-12079 | Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter | wedevs | Dokan Pro | Medium | 6.5 | 2026-06-25 03:42:21 | Deep Dive |
| CVE-2026-12077 | Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters | wedevs | Dokan Pro | High | 7.5 | 2026-06-25 03:42:21 | Deep Dive |
| CVE-2026-10833 | Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute | wpdevteam | Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns | Medium | 6.4 | 2026-06-25 03:42:20 | Deep Dive |
| CVE-2026-8658 | OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin | Rapid7 | InsightConnect Tcpdump Plugin | Medium | 6.0 | 2026-06-25 01:56:52 | Deep Dive |
| CVE-2026-8662 | Path Traversal in Rapid7 InsightConnect Compression Plugin | Rapid7 | InsightConnect Compression Plugin | Low | 3.3 | 2026-06-25 01:51:34 | Deep Dive |
| CVE-2026-8666 | OS Command Injection in Rapid7 InsightConnect Traceroute Plugin | Rapid7 | InsightConnect Traceroute Plugin | High | 7.7 | 2026-06-25 01:35:49 | Deep Dive |
| CVE-2026-8592 | OS Command Injection in Rapid7 InsightConnect AWK Plugin | Rapid7 | InsightConnect AWK Plugin | High | 7.7 | 2026-06-25 01:32:22 | Deep Dive |
| CVE-2026-8664 | OS Command Injection in Rapid7 InsightConnect Finger Plugin | Rapid7 | InsightConnect Finger Plugin | Medium | 6.0 | 2026-06-25 01:28:15 | Deep Dive |
| CVE-2026-8665 | OS Command Injection in Rapid7 InsightConnect Translate Plugin | Rapid7 | InsightConnect TR Plugin | High | 7.7 | 2026-06-25 01:12:01 | Deep Dive |
| CVE-2026-8660 | OS Command Injection in Rapid7 InsightConnect Ping Plugin | Rapid7 | InsightConnect Ping Plugin | High | 7.7 | 2026-06-25 00:52:34 | Deep Dive |
| CVE-2026-57589 | OpenBSD <=7.9 内核 UAF漏洞致权限提升 | OpenBSD | OpenBSD | High | 7.4 | 2026-06-25 00:33:05 | Deep Dive |
| CVE-2026-9153 | Arbitrary File Read in Rapid7 InsightConnect Sed Plugin | Rapid7 | InsightConnect Sed Plugin | Medium | 6.5 | 2026-06-25 00:33:03 | Deep Dive |
| CVE-2026-9154 | Arbitrary File Write in Rapid7 InsightConnect Sed Plugin | Rapid7 | InsightConnect Sed Plugin | High | 7.1 | 2026-06-25 00:29:30 | Deep Dive |