Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78139 | MEDIUM | 4.3 | The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all … | Aug 27, 2026 |
| CVE-2026-78138 | MEDIUM | 4.3 | The Finale Lite WordPress plugin before 2.21.0 does not perform a capability check on an AJAX action that returns a sales-campaign's configuration for an arbitrary … | Aug 27, 2026 |
| CVE-2026-78137 | HIGH | 7.5 | The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a … | Aug 27, 2026 |
| CVE-2026-78125 | MEDIUM | 5.3 | The LearnPress WordPress plugin before 4.0.3 does not perform any authorization check on one of its REST endpoints in all versions up to, and including, … | Aug 27, 2026 |
| CVE-2026-77991 | UNKNOWN | — | Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file … | Aug 27, 2026 |
| CVE-2026-77990 | UNKNOWN | — | Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee … | Aug 27, 2026 |
| CVE-2026-77989 | UNKNOWN | — | Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query … | Aug 27, 2026 |
| CVE-2026-77035 | UNKNOWN | — | Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with … | Aug 27, 2026 |
| CVE-2026-77034 | UNKNOWN | — | Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can … | Aug 27, 2026 |
| CVE-2026-77018 | HIGH | 8.8 | The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently … | Aug 27, 2026 |
| CVE-2026-77017 | HIGH | 7.7 | The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed … | Aug 27, 2026 |
| CVE-2026-77016 | CRITICAL | 9.6 | The Workeera WordPress plugin before 1.0.6 does not restrict which values may be written to a user's own candidate profile, and does not validate or … | Aug 27, 2026 |
| CVE-2026-76549 | MEDIUM | 5.9 | The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its backup management actions, which could … | Aug 27, 2026 |
| CVE-2026-59278 | MEDIUM | 6.5 | JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener … | Aug 27, 2026 |
| CVE-2026-59275 | MEDIUM | 6.6 | A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just the listener thread — full availability loss for every workload co-located … | Aug 27, 2026 |
| CVE-2026-59274 | MEDIUM | 6.5 | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust … | Aug 27, 2026 |
| CVE-2026-59271 | MEDIUM | 5.3 | When the RabbitMQ management aliveness check fails, the configured admin password is embedded in cleartext in the thrown exception message. Spring AMQP 4.1.0 Spring AMQP … | Aug 27, 2026 |
| CVE-2026-59270 | CRITICAL | 9.4 | Spring Security's embedded UnboundID LDAP server (UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces. Spring Security 7.1.0 Spring … | Aug 27, 2026 |
| CVE-2026-47894 | MEDIUM | 4.9 | Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring … | Aug 27, 2026 |
| CVE-2026-47893 | UNKNOWN | — | A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 … | Aug 27, 2026 |
| CVE-2026-47892 | UNKNOWN | — | A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 … | Aug 27, 2026 |
| CVE-2026-47891 | CRITICAL | 9.8 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 … | Aug 27, 2026 |
| CVE-2026-47890 | CRITICAL | 9.8 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework … | Aug 27, 2026 |
| CVE-2026-47889 | HIGH | 7.5 | A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework … | Aug 27, 2026 |
| CVE-2026-47888 | HIGH | 7.5 | A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 … | Aug 27, 2026 |