Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44710
Total
3597
Critical
13280
High
13130
Medium
CVE ID Severity Score Description Published
CVE-2026-79658 HIGH 7.5 Ech0 before 5.0.1 does not impose any size or shape limit on the Accept-Language header processed by its i18n middleware, which runs on every HTTP … Aug 25, 2026
CVE-2026-79657 CRITICAL 9.8 NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers … Aug 25, 2026
CVE-2026-78864 MEDIUM 6.3 A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey … Aug 25, 2026
CVE-2026-78684 MEDIUM 5.3 vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream … Aug 25, 2026
CVE-2026-77997 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to … Aug 25, 2026
CVE-2026-77996 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a … Aug 25, 2026
CVE-2026-77824 MEDIUM 4.9 The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, … Aug 25, 2026
CVE-2026-75971 HIGH 7.2 The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, … Aug 25, 2026
CVE-2026-75908 MEDIUM 4.3 The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not … Aug 25, 2026
CVE-2026-57910 UNKNOWN Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges. Aug 25, 2026
CVE-2026-57909 UNKNOWN A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system. Aug 25, 2026
CVE-2026-19949 HIGH 8.8 The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, … Aug 25, 2026
CVE-2026-18547 MEDIUM 6.4 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via … Aug 25, 2026
CVE-2026-17587 MEDIUM 5.3 The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and … Aug 25, 2026
CVE-2026-79652 MEDIUM 5.9 A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various … Aug 25, 2026
CVE-2026-78863 MEDIUM 6.3 A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. … Aug 25, 2026
CVE-2026-59335 HIGH 8.7 Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated … Aug 25, 2026
CVE-2026-55976 UNKNOWN Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause … Aug 25, 2026
CVE-2026-53561 UNKNOWN An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with … Aug 25, 2026
CVE-2026-49845 CRITICAL 9.8 SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore … Aug 25, 2026
CVE-2026-21758 LOW 3.7 HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment. Aug 25, 2026
CVE-2026-21754 MEDIUM 5.4 HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within … Aug 25, 2026
CVE-2026-21753 MEDIUM 4.2 HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the … Aug 25, 2026
CVE-2026-12600 UNKNOWN Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF … Aug 25, 2026
CVE-2026-78576 HIGH 7.5 The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied … Aug 25, 2026