Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49732
Total
4014
Critical
14766
High
14490
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11969 | MEDIUM | 4.9 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 … | Aug 05, 2026 |
| CVE-2026-11920 | MEDIUM | 4.9 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter … | Aug 05, 2026 |
| CVE-2026-11454 | MEDIUM | 6.5 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … | Aug 05, 2026 |
| CVE-2026-71201 | MEDIUM | 5.0 | In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by … | Aug 05, 2026 |
| CVE-2026-70375 | HIGH | 8.8 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), … | Aug 05, 2026 |
| CVE-2026-70374 | HIGH | 8.8 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file … | Aug 05, 2026 |
| CVE-2026-68080 | MEDIUM | 6.5 | It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive … | Aug 05, 2026 |
| CVE-2026-68078 | MEDIUM | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-68077 | UNKNOWN | — | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … | Aug 05, 2026 |
| CVE-2026-68075 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … | Aug 05, 2026 |
| CVE-2026-68073 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … | Aug 05, 2026 |
| CVE-2026-67592 | HIGH | 7.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-67591 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … | Aug 05, 2026 |
| CVE-2026-67590 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … | Aug 05, 2026 |
| CVE-2026-67555 | MEDIUM | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-67554 | MEDIUM | 6.5 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … | Aug 05, 2026 |
| CVE-2026-67553 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. … | Aug 05, 2026 |
| CVE-2026-67552 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. … | Aug 05, 2026 |
| CVE-2026-66277 | MEDIUM | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-66276 | UNKNOWN | — | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … | Aug 05, 2026 |
| CVE-2026-66275 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … | Aug 05, 2026 |
| CVE-2026-66274 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … | Aug 05, 2026 |
| CVE-2026-49004 | MEDIUM | 6.5 | The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with … | Aug 05, 2026 |
| CVE-2026-17515 | MEDIUM | 4.3 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of … | Aug 05, 2026 |
| CVE-2026-16993 | LOW | 3.7 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an … | Aug 05, 2026 |