Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44710
Total
3597
Critical
13280
High
13130
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-79658 | HIGH | 7.5 | Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP … | Aug 25, 2026 |
| CVE-2026-79657 | CRITICAL | 9.8 | NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers … | Aug 25, 2026 |
| CVE-2026-78864 | MEDIUM | 6.3 | A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey … | Aug 25, 2026 |
| CVE-2026-78684 | MEDIUM | 5.3 | vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream … | Aug 25, 2026 |
| CVE-2026-77997 | UNKNOWN | — | Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to … | Aug 25, 2026 |
| CVE-2026-77996 | UNKNOWN | — | Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a … | Aug 25, 2026 |
| CVE-2026-77824 | MEDIUM | 4.9 | The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, … | Aug 25, 2026 |
| CVE-2026-75971 | HIGH | 7.2 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … | Aug 25, 2026 |
| CVE-2026-75908 | MEDIUM | 4.3 | The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not … | Aug 25, 2026 |
| CVE-2026-57910 | UNKNOWN | — | Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. | Aug 25, 2026 |
| CVE-2026-57909 | UNKNOWN | — | A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. | Aug 25, 2026 |
| CVE-2026-19949 | HIGH | 8.8 | The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, … | Aug 25, 2026 |
| CVE-2026-18547 | MEDIUM | 6.4 | The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … | Aug 25, 2026 |
| CVE-2026-17587 | MEDIUM | 5.3 | The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … | Aug 25, 2026 |
| CVE-2026-79652 | MEDIUM | 5.9 | A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various … | Aug 25, 2026 |
| CVE-2026-78863 | MEDIUM | 6.3 | A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. … | Aug 25, 2026 |
| CVE-2026-59335 | HIGH | 8.7 | Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated … | Aug 25, 2026 |
| CVE-2026-55976 | UNKNOWN | — | Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause … | Aug 25, 2026 |
| CVE-2026-53561 | UNKNOWN | — | An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with … | Aug 25, 2026 |
| CVE-2026-49845 | CRITICAL | 9.8 | SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore … | Aug 25, 2026 |
| CVE-2026-21758 | LOW | 3.7 | HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. | Aug 25, 2026 |
| CVE-2026-21754 | MEDIUM | 5.4 | HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within … | Aug 25, 2026 |
| CVE-2026-21753 | MEDIUM | 4.2 | HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the … | Aug 25, 2026 |
| CVE-2026-12600 | UNKNOWN | — | Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF … | Aug 25, 2026 |
| CVE-2026-78576 | HIGH | 7.5 | The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied … | Aug 25, 2026 |