CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-21759 published: HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increas...
View full advisory →CVE-2026-59295 published: Micrometer-instrumented Apache HttpAsyncClient (4.x or 5.x) usage via MicrometerHttpClientInterceptor can leak memory unboundedly when as...
View full advisory →CVE-2026-10618 published: Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without es...
View full advisory →CVE-2026-8173 published: The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated admini...
View full advisory →CVE-2026-78200 published: A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.ph...
View full advisory →CVE-2026-78186 published: A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. Th...
View full advisory →CVE-2026-78196 published: A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoSh...
View full advisory →CVE-2026-78185 published: A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pag...
View full advisory →CVE-2026-19852 published: NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbit...
View full advisory →CVE-2026-19853 published: NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a sp...
View full advisory →CVE-2026-78179 published: A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the fil...
View full advisory →CVE-2026-78177 published: A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/dev...
View full advisory →CVE-2026-78166 published: A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the...
View full advisory →CVE-2026-78204 published: Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test...
View full advisory →CVE-2026-78160 published: A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/...
View full advisory →CVE-2026-78205 published: BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP address...
View full advisory →