CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-32554 published: Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
View full advisory →CVE-2026-32555 published: Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
View full advisory →CVE-2026-32556 published: Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
View full advisory →CVE-2026-32559 published: Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
View full advisory →CVE-2026-17113 published: A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` ...
View full advisory →CVE-2026-77567 published: Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are e...
View full advisory →CVE-2026-75464 published: OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
View full advisory →CVE-2026-75542 published: Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API key is exchanged for a token through the OAuth client_creden...
View full advisory →CVE-2026-75554 published: Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private packages. expand_repositories_scope/3 in lib/hexpm/permissions.ex only rewrites the literal...
View full advisory →CVE-2026-5006 published: A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can contro...
View full advisory →CVE-2026-56135 published: In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow i...
View full advisory →CVE-2026-56136 published: In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered b...
View full advisory →CVE-2026-55468 published: Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access contr...
View full advisory →CVE-2026-52490 published: An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
View full advisory →CVE-2026-52492 published: An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
View full advisory →CVE-2026-16783 published: A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the ...
View full advisory →CVE-2026-19568 published: A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
View full advisory →CVE-2026-16781 published: A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.
View full advisory →CVE-2026-16782 published: A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the cur...
View full advisory →CVE-2022-30983 published: A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
View full advisory →