Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49732
Total
4014
Critical
14766
High
14490
Medium
CVE ID Severity Score Description Published
CVE-2026-11969 MEDIUM 4.9 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Parameter in all versions up to, and including, 14.3 … Aug 05, 2026
CVE-2026-11920 MEDIUM 4.9 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via the 'order' parameter … Aug 05, 2026
CVE-2026-11454 MEDIUM 6.5 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, … Aug 05, 2026
CVE-2026-71201 MEDIUM 5.0 In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by … Aug 05, 2026
CVE-2026-70375 HIGH 8.8 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), … Aug 05, 2026
CVE-2026-70374 HIGH 8.8 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file … Aug 05, 2026
CVE-2026-68080 MEDIUM 6.5 It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive … Aug 05, 2026
CVE-2026-68078 MEDIUM 6.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-68077 UNKNOWN An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … Aug 05, 2026
CVE-2026-68075 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … Aug 05, 2026
CVE-2026-68073 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … Aug 05, 2026
CVE-2026-67592 HIGH 7.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-67591 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … Aug 05, 2026
CVE-2026-67590 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … Aug 05, 2026
CVE-2026-67555 MEDIUM 6.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-67554 MEDIUM 6.5 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … Aug 05, 2026
CVE-2026-67553 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. … Aug 05, 2026
CVE-2026-67552 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. … Aug 05, 2026
CVE-2026-66277 MEDIUM 6.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-66276 UNKNOWN An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … Aug 05, 2026
CVE-2026-66275 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … Aug 05, 2026
CVE-2026-66274 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … Aug 05, 2026
CVE-2026-49004 MEDIUM 6.5 The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with … Aug 05, 2026
CVE-2026-17515 MEDIUM 4.3 The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of … Aug 05, 2026
CVE-2026-16993 LOW 3.7 The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an … Aug 05, 2026