Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
50169
Total
4054
Critical
14909
High
14667
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-15675 | UNKNOWN | — | The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields before outputting it in an HTML attribute, … | Aug 02, 2026 |
| CVE-2026-9335 | MEDIUM | 6.5 | A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` … | Aug 02, 2026 |
| CVE-2026-8457 | CRITICAL | 9.8 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to … | Aug 02, 2026 |
| CVE-2026-18352 | HIGH | 7.5 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. … | Aug 02, 2026 |
| CVE-2026-13339 | HIGH | 7.5 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes … | Aug 02, 2026 |
| CVE-2026-17002 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 01, 2026 |
| CVE-2026-18556 | UNKNOWN | — | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. | Aug 01, 2026 |
| CVE-2026-55735 | UNKNOWN | — | Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticated attacker to revoke a victim's session with a forged token. Guardian.revoke/3 in lib/guardian.ex decodes … | Aug 01, 2026 |
| CVE-2026-55734 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guardian.Permissions module) allows a denial of service via BEAM atom-table exhaustion. This vulnerability is … | Aug 01, 2026 |
| CVE-2026-55733 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-controlled binary input. Guardian.Permissions.AtomEncoding encodes permission … | Aug 01, 2026 |
| CVE-2026-54894 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of service via unbounded atom creation from attacker-influenced binary input. Guardian.Plug.Keys derives connection … | Aug 01, 2026 |
| CVE-2026-67355 | MEDIUM | 5.9 | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers … | Aug 01, 2026 |
| CVE-2026-67354 | MEDIUM | 5.9 | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the … | Aug 01, 2026 |
| CVE-2026-67353 | MEDIUM | 5.3 | guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can … | Aug 01, 2026 |
| CVE-2026-67352 | HIGH | 7.6 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS … | Aug 01, 2026 |
| CVE-2026-67344 | MEDIUM | 4.3 | ArcadeDB before 26.7.2 fails to enforce the UPDATE_SCHEMA database permission on the ALTER TYPE ... CUSTOM and ALTER TYPE ... BUCKETSELECTIONSTRATEGY SQL operations, which map … | Aug 01, 2026 |
| CVE-2026-67343 | HIGH | 8.8 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in … | Aug 01, 2026 |
| CVE-2026-67342 | CRITICAL | 9.8 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database … | Aug 01, 2026 |
| CVE-2026-67341 | CRITICAL | 9.8 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute … | Aug 01, 2026 |
| CVE-2026-67340 | CRITICAL | 9.8 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An … | Aug 01, 2026 |
| CVE-2026-67339 | MEDIUM | 5.3 | guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access … | Aug 01, 2026 |
| CVE-2026-67338 | MEDIUM | 6.1 | JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package metadata URLs. Attackers can … | Aug 01, 2026 |
| CVE-2026-67337 | MEDIUM | 6.5 | better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid primary credentials can access authenticated routes without completing … | Aug 01, 2026 |
| CVE-2026-67336 | HIGH | 8.7 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. … | Aug 01, 2026 |
| CVE-2026-67335 | MEDIUM | 5.3 | better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without PKCE. Attackers can forge … | Aug 01, 2026 |