Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43999
Total
3569
Critical
13202
High
13005
Medium
CVE ID Severity Score Description Published
CVE-2026-19949 HIGH 8.8 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, … Aug 25, 2026
CVE-2026-18547 MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Aug 25, 2026
CVE-2026-17587 MEDIUM 5.3 The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … Aug 25, 2026
CVE-2026-79652 MEDIUM 5.9 A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various … Aug 25, 2026
CVE-2026-78863 MEDIUM 6.3 A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. … Aug 25, 2026
CVE-2026-59335 HIGH 8.7 Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated … Aug 25, 2026
CVE-2026-55976 UNKNOWN Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause … Aug 25, 2026
CVE-2026-53561 UNKNOWN An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with … Aug 25, 2026
CVE-2026-49845 CRITICAL 9.8 SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore … Aug 25, 2026
CVE-2026-21758 LOW 3.7 HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. Aug 25, 2026
CVE-2026-21754 MEDIUM 5.4 HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within … Aug 25, 2026
CVE-2026-21753 MEDIUM 4.2 HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the … Aug 25, 2026
CVE-2026-12600 UNKNOWN Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF … Aug 25, 2026
CVE-2026-78576 HIGH 7.5 The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied … Aug 25, 2026
CVE-2026-78572 HIGH 8.1 The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. … Aug 25, 2026
CVE-2026-78570 CRITICAL 9.8 The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated … Aug 25, 2026
CVE-2026-76128 MEDIUM 6.4 The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 … Aug 25, 2026
CVE-2026-75038 MEDIUM 6.1 UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0. Aug 25, 2026
CVE-2026-75037 HIGH 7.0 Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit … Aug 25, 2026
CVE-2026-49050 HIGH 8.8 General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which … Aug 25, 2026
CVE-2026-16231 HIGH 8.1 hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during … Aug 25, 2026
CVE-2026-12878 UNKNOWN In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions. Aug 25, 2026
CVE-2026-78568 CRITICAL 9.8 The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the … Aug 25, 2026
CVE-2026-78566 HIGH 8.1 The Shuffle theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.8. This makes it possible for unauthenticated … Aug 25, 2026
CVE-2026-78563 HIGH 7.2 The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization … Aug 25, 2026