CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-78864 MEDIUM

CVE-2026-78864 published: A vulnerability was determined in liketrek TREK up to 3.0.22. The affected element is the function journeyService.updateEntry of the file server/src/nest/journey/journey.controller.t of the component Journey Entry Update. This manipulation causes sql inject...

View full advisory →
CVE-2026-79657 CRITICAL

CVE-2026-79657 published: NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entire module namespaces instead of specific safe callables. Attackers can craft malicious pickle payloads invoking dangerous in-namespace fun...

View full advisory →
CVE-2026-78684 MEDIUM

CVE-2026-78684 published: vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate DeepStream at request time to initialize the process-wide GPU decode pool and submit video...

View full advisory →
CVE-2026-77997 UNKNOWN

CVE-2026-77997 published: Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A missing access check allowed users with com_template editing permissions to access information about arbitrary modules without the respective...

View full advisory →
CVE-2026-75971 HIGH

CVE-2026-75971 published: The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.9.4. This is due to the `rum_importer()` function being registered on the...

View full advisory →
CVE-2026-77824 MEDIUM

CVE-2026-77824 published: The Media Sweep – WordPress Media Cleaner plugin for WordPress is vulnerable to generic SQL Injection via the 'fields' parameter in all versions up to, and including, 1.1.3 due to insufficient escaping on the user supplied parameter and lack of sufficient p...

View full advisory →
CVE-2026-77996 UNKNOWN

CVE-2026-77996 published: Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping in the location custom field lead to a XSS vector.

View full advisory →
CVE-2026-57909 UNKNOWN

CVE-2026-57909 published: A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to execute arbitrary code on an affected system.

View full advisory →
CVE-2026-57910 UNKNOWN

CVE-2026-57910 published: Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.

View full advisory →
CVE-2026-75908 MEDIUM

CVE-2026-75908 published: The Newsletters plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.17. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated ...

View full advisory →
CVE-2026-18547 MEDIUM

CVE-2026-18547 published: The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Textarea Profile Field with HTML Support (DOM Gadget via id Attribute) i...

View full advisory →
CVE-2026-19949 HIGH

CVE-2026-19949 published: The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa...

View full advisory →
CVE-2026-17587 MEDIUM

CVE-2026-17587 published: The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.6. This is due to the plugin not properly verifying that a user is authorized to perform an acti...

View full advisory →
CVE-2026-78863 MEDIUM

CVE-2026-78863 published: A vulnerability was found in liketrek TREK up to 3.0.22. Impacted is the function loginUser of the file server/src/services/authService.ts of the component Pre-2FA mfa_token Handler. The manipulation results in improper authentication. The attack may be per...

View full advisory →
CVE-2026-79652 MEDIUM

CVE-2026-79652 published: A flaw was found in the JWT Bearer authorization grant implementation within the keycloak-services component of Red Hat Build of Keycloak. This component handles various OAuth2 and OpenID Connect grant types used for issuing access tokens. The issue occurs ...

View full advisory →
CVE-2026-55976 CRITICAL

CVE-2026-55976 published: Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.ur...

View full advisory →
CVE-2026-59335 HIGH

CVE-2026-59335 published: Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restriction that...

View full advisory →
CVE-2026-49845 CRITICAL

CVE-2026-49845 published: SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics up...

View full advisory →
CVE-2026-53561 HIGH

CVE-2026-53561 published: An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated netwo...

View full advisory →
CVE-2026-21753 MEDIUM

CVE-2026-21753 published: HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.

View full advisory →