Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49732
Total
4014
Critical
14766
High
14490
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44945 | CRITICAL | 9.1 | A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access … | Aug 05, 2026 |
| CVE-2026-25703 | HIGH | 7.3 | NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing sensitive information. | Aug 05, 2026 |
| CVE-2026-15452 | MEDIUM | 4.7 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query String in … | Aug 05, 2026 |
| CVE-2026-0931 | UNKNOWN | — | Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process to crash and fail to restart. | Aug 05, 2026 |
| CVE-2026-8029 | LOW | 3.9 | The ZTE Smart Life app contains an SQL injection vulnerability that allows attackers to execute UNION SELECT statements to query sensitive data in the feedback.db … | Aug 05, 2026 |
| CVE-2026-10090 | CRITICAL | 9.9 | A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges … | Aug 05, 2026 |
| CVE-2026-10059 | CRITICAL | 9.1 | A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a … | Aug 05, 2026 |
| CVE-2026-7726 | MEDIUM | 6.5 | The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync()` callback registered via `wp_ajax_nopriv_handle_sync` … | Aug 05, 2026 |
| CVE-2026-7693 | HIGH | 7.2 | The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of … | Aug 05, 2026 |
| CVE-2026-7520 | HIGH | 8.1 | The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and … | Aug 05, 2026 |
| CVE-2026-7444 | HIGH | 8.1 | The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due … | Aug 05, 2026 |
| CVE-2026-7441 | MEDIUM | 6.4 | The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `posttype` attribute of the `SimpleYearlyArchive` shortcode in all versions up … | Aug 05, 2026 |
| CVE-2026-7105 | MEDIUM | 4.3 | The Xpro Addons plugin for WordPress is vulnerable to unauthorized creation of data due to a missing capability check on the `get_menu_content_editor()` function in all … | Aug 05, 2026 |
| CVE-2026-71215 | HIGH | 7.5 | art-template's sub-template resolution logic (src/compile/adapter/resolve-filename.js), used by both the include() and extend() template directives, resolves the target file path via path.resolve(root, filename) with no check … | Aug 05, 2026 |
| CVE-2026-71214 | CRITICAL | 9.8 | The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraSession(), which prefers a session_variables object taken directly from the client-supplied JSON … | Aug 05, 2026 |
| CVE-2026-71213 | CRITICAL | 9.1 | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated … | Aug 05, 2026 |
| CVE-2026-71212 | MEDIUM | 4.4 | xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py) by appending the user-provided or scanned URL as a bare trailing positional … | Aug 05, 2026 |
| CVE-2026-71211 | HIGH | 7.1 | MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of scheme, host, or IP range; the value … | Aug 05, 2026 |
| CVE-2026-71210 | MEDIUM | 5.3 | Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the resolved IP against private-range rules, but then issues the actual outbound HTTP request … | Aug 05, 2026 |
| CVE-2026-71209 | HIGH | 7.5 | audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences … | Aug 05, 2026 |
| CVE-2026-71208 | MEDIUM | 6.5 | KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed … | Aug 05, 2026 |
| CVE-2026-71207 | CRITICAL | 9.8 | The Stock-Inventory-Management-System application's login.php assigns raw $_POST username/password values to $_SESSION and builds its authentication query by directly concatenating those session values into a SQL … | Aug 05, 2026 |
| CVE-2026-71206 | HIGH | 8.3 | Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No … | Aug 05, 2026 |
| CVE-2026-71205 | MEDIUM | 6.5 | changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting … | Aug 05, 2026 |
| CVE-2026-71204 | MEDIUM | 6.2 | changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update(). Because WTForms represents an unchecked … | Aug 05, 2026 |