In GitLab CE/EE versions from 17.1 before 18.6.4, 18.7 before 18.7.2 and 18.8 before 18.8.2 a medium severity vulnerability CVE-2025-13335 was detected. This vulnerability allows an authenticated attacker to cause a denial of service by configuring malformed Wiki documents that bypass cycle detection and trigger an infinite loop with an unreachable exit condition. To address this issue, users should upgrade GitLab to versions 18.6.4, 18.7.2, 18.8.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-13335.
Read more Newsflash Developer ToolsIn Oracle MySQL Server Thread Pooling component versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7 and 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21964 was detected. This vulnerability allows a high-privileged attacker with network access to cause a complete denial of service by triggering a hang or repeated crashes of the MySQL Server. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21964.
Read more Newsflash DatabaseIn Oracle MySQL Server versions 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21952 was detected. This vulnerability allows a high-privileged attacker with network access to cause a hang or a repeatedly reproducible crash, resulting in a complete denial of service (DoS) of the MySQL Server due to an issue in the Server Parser component. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21952.
Read more Newsflash DatabaseIn Oracle MySQL Server InnoDB component versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7 and 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21936 was detected. This vulnerability allows a high-privileged attacker with network access to cause a hang or repeatedly crash the MySQL Server, resulting in a complete denial of service. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21936.
Read more NewsflashIn Oracle MySQL Server Optimizer component versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7 and 9.0.0 through 9.5.0 a medium severity vulnerability CVE-2026-21968 was detected. This vulnerability allows a low-privileged attacker with network access to cause a hang or repeatedly crash the MySQL Server, resulting in a complete denial of service. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-21968.
Read more Newsflash DatabaseIn the WP Hello Bar plugin for WordPress versions up to and including 1.02 a medium severity vulnerability CVE-2026-1042 was detected. This vulnerability allows authenticated attackers with administrator-level access and above to inject arbitrary web scripts through the digit_one and digit_two parameters due to insufficient input sanitization and output escaping, resulting in stored cross-site scripting that executes when users access affected pages. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1042.
Read more CMS NewsflashIn the Viet Contact plugin for WordPress versions up to and including 1.3.2 a medium severity vulnerability CVE-2026-1045 was detected. This vulnerability allows authenticated attackers with administrator-level permissions and above to perform stored cross-site scripting (XSS) by injecting arbitrary web scripts through improperly sanitized admin settings, which execute when a user accesses the affected pages. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-1045.
Read more CMS NewsflashIn Umbraco CMS version 8.14.1 a medium severity vulnerability CVE-2021-47776 was detected. This vulnerability allows attackers to perform server-side request forgery (SSRF) by manipulating the baseUrl parameter in multiple dashboard and help controller endpoints, causing the server to initiate unauthorized requests to external hosts. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2021-47776.
Read more CMS NewsflashIn Traefik versions prior to 2.11.35 and 3.6.7 a medium severity vulnerability CVE-2026-22045 was detected. This vulnerability allows unauthenticated attackers to cause a denial of service by opening multiple ACME TLS-ALPN connections and stalling the handshake, indefinitely tying up goroutines and file descriptors when automatic certificate generation is enabled. To address this issue, users should upgrade Traefik to version 2.11.35 or 3.6.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-22045.
Read more Newsflash Infrastructure and Network Security