Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-18329 | HIGH | 8.2 | Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown … | Sep 02, 2026 |
| CVE-2026-18058 | HIGH | 7.5 | The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in … | Sep 02, 2026 |
| CVE-2026-14199 | HIGH | 7.1 | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the … | Sep 02, 2026 |
| CVE-2026-12704 | MEDIUM | 6.8 | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. … | Sep 02, 2026 |
| CVE-2026-8151 | MEDIUM | 5.4 | The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator … | Sep 02, 2026 |
| CVE-2026-83547 | MEDIUM | 6.8 | The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow … | Sep 02, 2026 |
| CVE-2026-83533 | MEDIUM | 5.3 | The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing … | Sep 02, 2026 |
| CVE-2026-82955 | UNKNOWN | — | In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component … | Sep 02, 2026 |
| CVE-2026-82884 | MEDIUM | 6.8 | The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the … | Sep 02, 2026 |
| CVE-2026-82293 | MEDIUM | 4.3 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An … | Sep 02, 2026 |
| CVE-2026-81571 | MEDIUM | 4.8 | The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, … | Sep 02, 2026 |
| CVE-2026-79991 | UNKNOWN | — | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the … | Sep 02, 2026 |
| CVE-2026-79990 | UNKNOWN | — | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the … | Sep 02, 2026 |
| CVE-2026-79989 | UNKNOWN | — | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows … | Sep 02, 2026 |
| CVE-2026-78609 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes … | Sep 02, 2026 |
| CVE-2026-78604 | HIGH | 7.8 | Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic … | Sep 02, 2026 |
| CVE-2026-78602 | MEDIUM | 5.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). … | Sep 02, 2026 |
| CVE-2026-78601 | MEDIUM | 5.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store … | Sep 02, 2026 |
| CVE-2026-78600 | LOW | 3.5 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association … | Sep 02, 2026 |
| CVE-2026-78599 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal … | Sep 02, 2026 |
| CVE-2026-78598 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated … | Sep 02, 2026 |
| CVE-2026-78594 | MEDIUM | 4.9 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user … | Sep 02, 2026 |
| CVE-2026-78591 | MEDIUM | 6.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources … | Sep 02, 2026 |
| CVE-2026-78590 | HIGH | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged … | Sep 02, 2026 |
| CVE-2026-78588 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to … | Sep 02, 2026 |