Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19949 | HIGH | 8.8 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, … | Aug 25, 2026 |
| CVE-2026-18547 | MEDIUM | 6.4 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Aug 25, 2026 |
| CVE-2026-17587 | MEDIUM | 5.3 | The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … | Aug 25, 2026 |
| CVE-2026-79652 | MEDIUM | 5.9 | A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various … | Aug 25, 2026 |
| CVE-2026-78863 | MEDIUM | 6.3 | A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. … | Aug 25, 2026 |
| CVE-2026-59335 | HIGH | 8.7 | Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated … | Aug 25, 2026 |
| CVE-2026-55976 | UNKNOWN | — | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause … | Aug 25, 2026 |
| CVE-2026-53561 | UNKNOWN | — | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with … | Aug 25, 2026 |
| CVE-2026-49845 | CRITICAL | 9.8 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore … | Aug 25, 2026 |
| CVE-2026-21758 | LOW | 3.7 | HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. | Aug 25, 2026 |
| CVE-2026-21754 | MEDIUM | 5.4 | HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within … | Aug 25, 2026 |
| CVE-2026-21753 | MEDIUM | 4.2 | HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the … | Aug 25, 2026 |
| CVE-2026-12600 | UNKNOWN | — | Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF … | Aug 25, 2026 |
| CVE-2026-78576 | HIGH | 7.5 | The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied … | Aug 25, 2026 |
| CVE-2026-78572 | HIGH | 8.1 | The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. … | Aug 25, 2026 |
| CVE-2026-78570 | CRITICAL | 9.8 | The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated … | Aug 25, 2026 |
| CVE-2026-76128 | MEDIUM | 6.4 | The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 … | Aug 25, 2026 |
| CVE-2026-75038 | MEDIUM | 6.1 | UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0. | Aug 25, 2026 |
| CVE-2026-75037 | HIGH | 7.0 | Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit … | Aug 25, 2026 |
| CVE-2026-49050 | HIGH | 8.8 | General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which … | Aug 25, 2026 |
| CVE-2026-16231 | HIGH | 8.1 | hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during … | Aug 25, 2026 |
| CVE-2026-12878 | UNKNOWN | — | In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. | Aug 25, 2026 |
| CVE-2026-78568 | CRITICAL | 9.8 | The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the … | Aug 25, 2026 |
| CVE-2026-78566 | HIGH | 8.1 | The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated … | Aug 25, 2026 |
| CVE-2026-78563 | HIGH | 7.2 | The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization … | Aug 25, 2026 |