Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
27197
Total
2065
Critical
8240
High
8439
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11420 | UNKNOWN | — | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any … | Jun 05, 2026 |
| CVE-2026-11419 | UNKNOWN | — | A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload … | Jun 05, 2026 |
| CVE-2026-11414 | UNKNOWN | — | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across … | Jun 05, 2026 |
| CVE-2026-11401 | HIGH | 8.0 | An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor … | Jun 05, 2026 |
| CVE-2026-11400 | HIGH | 8.0 | An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor … | Jun 05, 2026 |
| CVE-2026-5415 | HIGH | 8.8 | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication … | Jun 05, 2026 |
| CVE-2026-5411 | HIGH | 8.8 | The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary … | Jun 05, 2026 |
| CVE-2026-46511 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an attack chain utilizing Stored XSS alongside dynamic token exposure … | Jun 05, 2026 |
| CVE-2026-46496 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to … | Jun 05, 2026 |
| CVE-2026-46399 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 has an authenticated file … | Jun 05, 2026 |
| CVE-2026-46396 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to … | Jun 05, 2026 |
| CVE-2026-46395 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two … | Jun 05, 2026 |
| CVE-2026-46394 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vulnerability exists in the Git.php library … | Jun 05, 2026 |
| CVE-2026-46393 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. An authenticated Server-Side Request Forgery (SSRF) vulnerability in versions prior to 26.0.0 allows authenticated … | Jun 05, 2026 |
| CVE-2026-46392 | HIGH | 8.7 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions … | Jun 05, 2026 |
| CVE-2026-46391 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 9.0.1 and prior to version 26.0.0 of @haxtheweb/open-apis, multiple functions conduct … | Jun 05, 2026 |
| CVE-2026-46390 | UNKNOWN | — | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0.0, the gitlist plugin is exposed … | Jun 05, 2026 |
| CVE-2026-46389 | CRITICAL | 10.0 | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a … | Jun 05, 2026 |
| CVE-2026-10580 | CRITICAL | 9.8 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and … | Jun 05, 2026 |
| CVE-2026-50733 | HIGH | 8.8 | Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path … | Jun 05, 2026 |
| CVE-2026-49493 | HIGH | 8.8 | Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. … | Jun 05, 2026 |
| CVE-2026-49492 | HIGH | 8.8 | Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the … | Jun 05, 2026 |
| CVE-2026-45750 | CRITICAL | 9.0 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in the … | Jun 05, 2026 |
| CVE-2026-45749 | HIGH | 8.1 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior … | Jun 05, 2026 |
| CVE-2026-45748 | CRITICAL | 9.8 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 … | Jun 05, 2026 |