Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42028
Total
3422
Critical
12413
High
12340
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-82293 | MEDIUM | 4.3 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An … | Sep 02, 2026 |
| CVE-2026-81571 | MEDIUM | 4.8 | The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, … | Sep 02, 2026 |
| CVE-2026-79991 | UNKNOWN | — | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the … | Sep 02, 2026 |
| CVE-2026-79990 | UNKNOWN | — | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the … | Sep 02, 2026 |
| CVE-2026-79989 | UNKNOWN | — | The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows … | Sep 02, 2026 |
| CVE-2026-78609 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes … | Sep 02, 2026 |
| CVE-2026-78604 | HIGH | 7.8 | Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic … | Sep 02, 2026 |
| CVE-2026-78602 | MEDIUM | 5.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). … | Sep 02, 2026 |
| CVE-2026-78601 | MEDIUM | 5.5 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store … | Sep 02, 2026 |
| CVE-2026-78600 | LOW | 3.5 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association … | Sep 02, 2026 |
| CVE-2026-78599 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal … | Sep 02, 2026 |
| CVE-2026-78598 | MEDIUM | 5.4 | Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated … | Sep 02, 2026 |
| CVE-2026-78594 | MEDIUM | 4.9 | Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user … | Sep 02, 2026 |
| CVE-2026-78591 | MEDIUM | 6.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources … | Sep 02, 2026 |
| CVE-2026-78590 | HIGH | 7.3 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged … | Sep 02, 2026 |
| CVE-2026-78588 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to … | Sep 02, 2026 |
| CVE-2026-78587 | LOW | 3.1 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not … | Sep 02, 2026 |
| CVE-2026-78586 | MEDIUM | 6.5 | Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with … | Sep 02, 2026 |
| CVE-2026-78584 | MEDIUM | 4.3 | Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery … | Sep 02, 2026 |
| CVE-2026-78153 | MEDIUM | 5.3 | The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, … | Sep 02, 2026 |
| CVE-2026-77794 | MEDIUM | 5.3 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users … | Sep 02, 2026 |
| CVE-2026-77793 | MEDIUM | 5.3 | The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration … | Sep 02, 2026 |
| CVE-2026-77009 | CRITICAL | 9.9 | The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as … | Sep 02, 2026 |
| CVE-2026-4357 | CRITICAL | 10.0 | The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be … | Sep 02, 2026 |
| CVE-2026-2811 | MEDIUM | 5.4 | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This … | Sep 02, 2026 |