Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-70375 | HIGH | 8.8 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), … | Aug 05, 2026 |
| CVE-2026-70374 | HIGH | 8.8 | HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file … | Aug 05, 2026 |
| CVE-2026-68080 | MEDIUM | 6.5 | It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive … | Aug 05, 2026 |
| CVE-2026-68078 | MEDIUM | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-68077 | UNKNOWN | — | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … | Aug 05, 2026 |
| CVE-2026-68075 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … | Aug 05, 2026 |
| CVE-2026-68073 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … | Aug 05, 2026 |
| CVE-2026-67592 | HIGH | 7.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-67591 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … | Aug 05, 2026 |
| CVE-2026-67590 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … | Aug 05, 2026 |
| CVE-2026-67555 | MEDIUM | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-67554 | MEDIUM | 6.5 | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … | Aug 05, 2026 |
| CVE-2026-67553 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. … | Aug 05, 2026 |
| CVE-2026-67552 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. … | Aug 05, 2026 |
| CVE-2026-66277 | MEDIUM | 6.5 | It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … | Aug 05, 2026 |
| CVE-2026-66276 | UNKNOWN | — | An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … | Aug 05, 2026 |
| CVE-2026-66275 | UNKNOWN | — | An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … | Aug 05, 2026 |
| CVE-2026-66274 | UNKNOWN | — | A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … | Aug 05, 2026 |
| CVE-2026-49004 | MEDIUM | 6.5 | The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with … | Aug 05, 2026 |
| CVE-2026-17515 | MEDIUM | 4.3 | The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of … | Aug 05, 2026 |
| CVE-2026-16993 | LOW | 3.7 | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an … | Aug 05, 2026 |
| CVE-2026-16981 | UNKNOWN | — | The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one … | Aug 05, 2026 |
| CVE-2026-16968 | MEDIUM | 6.5 | The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access … | Aug 05, 2026 |
| CVE-2026-16942 | MEDIUM | 5.4 | The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to … | Aug 05, 2026 |
| CVE-2026-16940 | UNKNOWN | — | The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the … | Aug 05, 2026 |