Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-56093 | UNKNOWN | — | The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A … | Aug 25, 2026 |
| CVE-2026-56092 | UNKNOWN | — | The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, … | Aug 25, 2026 |
| CVE-2026-17548 | UNKNOWN | — | Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view … | Aug 25, 2026 |
| CVE-2026-78701 | MEDIUM | 6.5 | A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By … | Aug 25, 2026 |
| CVE-2026-78322 | MEDIUM | 6.5 | A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, … | Aug 25, 2026 |
| CVE-2026-67578 | HIGH | 7.5 | FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter … | Aug 25, 2026 |
| CVE-2026-66882 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. … | Aug 25, 2026 |
| CVE-2026-65633 | UNKNOWN | — | Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The … | Aug 25, 2026 |
| CVE-2026-59769 | CRITICAL | 9.1 | FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen … | Aug 25, 2026 |
| CVE-2026-19851 | HIGH | 7.7 | A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created … | Aug 25, 2026 |
| CVE-2026-18512 | MEDIUM | 6.4 | The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation … | Aug 25, 2026 |
| CVE-2026-18328 | HIGH | 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' … | Aug 25, 2026 |
| CVE-2026-18323 | HIGH | 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save … | Aug 25, 2026 |
| CVE-2026-18100 | MEDIUM | 6.4 | The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget … | Aug 25, 2026 |
| CVE-2026-16601 | HIGH | 8.8 | The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in … | Aug 25, 2026 |
| CVE-2026-78656 | MEDIUM | 6.3 | A vulnerability was found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_del.php. The manipulation of the argument … | Aug 25, 2026 |
| CVE-2026-69665 | HIGH | 7.8 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in … | Aug 25, 2026 |
| CVE-2026-68960 | HIGH | 8.5 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in … | Aug 25, 2026 |
| CVE-2026-68959 | HIGH | 8.5 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a … | Aug 25, 2026 |
| CVE-2026-68062 | HIGH | 8.5 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a … | Aug 25, 2026 |
| CVE-2026-66109 | HIGH | 7.8 | A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to … | Aug 25, 2026 |
| CVE-2026-78654 | HIGH | 7.3 | A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads … | Aug 25, 2026 |
| CVE-2026-78638 | LOW | 3.3 | A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component … | Aug 25, 2026 |
| CVE-2026-78478 | HIGH | 8.1 | The Mane theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7. This makes it possible for unauthenticated … | Aug 25, 2026 |
| CVE-2026-78477 | CRITICAL | 9.8 | The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers … | Aug 25, 2026 |