Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49853
Total
4028
Critical
14819
High
14575
Medium
CVE ID Severity Score Description Published
CVE-2026-70375 HIGH 8.8 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo() in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec(`git checkout ${this.branch || 'master'}`), … Aug 05, 2026
CVE-2026-70374 HIGH 8.8 HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail() in src/Server/Entity/Resource/Media.js builds a temporary file … Aug 05, 2026
CVE-2026-68080 MEDIUM 6.5 It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive … Aug 05, 2026
CVE-2026-68078 MEDIUM 6.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-68077 UNKNOWN An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … Aug 05, 2026
CVE-2026-68075 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … Aug 05, 2026
CVE-2026-68073 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. … Aug 05, 2026
CVE-2026-67592 HIGH 7.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-67591 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … Aug 05, 2026
CVE-2026-67590 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. … Aug 05, 2026
CVE-2026-67555 MEDIUM 6.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-67554 MEDIUM 6.5 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … Aug 05, 2026
CVE-2026-67553 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. … Aug 05, 2026
CVE-2026-67552 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-Dotnet through 1.0.0. … Aug 05, 2026
CVE-2026-66277 MEDIUM 6.5 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and … Aug 05, 2026
CVE-2026-66276 UNKNOWN An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading to denial … Aug 05, 2026
CVE-2026-66275 UNKNOWN An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … Aug 05, 2026
CVE-2026-66274 UNKNOWN A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. … Aug 05, 2026
CVE-2026-49004 MEDIUM 6.5 The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens on a specific port, runs with … Aug 05, 2026
CVE-2026-17515 MEDIUM 4.3 The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPress plugin before 7.0.4 does not have authorisation and CSRF checks in one of … Aug 05, 2026
CVE-2026-16993 LOW 3.7 The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage directory with server-independent access control, relying only on an … Aug 05, 2026
CVE-2026-16981 UNKNOWN The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or ownership check) on one … Aug 05, 2026
CVE-2026-16968 MEDIUM 6.5 The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access … Aug 05, 2026
CVE-2026-16942 MEDIUM 5.4 The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to … Aug 05, 2026
CVE-2026-16940 UNKNOWN The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the … Aug 05, 2026