CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-17033 published: An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert containing a controlled generatorURL. The attacker is authorized to create the alert, but not to execute script in another user's Grafan...
View full advisory →CVE-2025-68833 published: HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources.
View full advisory →CVE-2026-78365 published: Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT reque...
View full advisory →CVE-2026-78247 published: A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can...
View full advisory →CVE-2026-21756 published: HCL Hive is affected by a broken access control vulnerability which could allow an attacker or unauthorized user to introduce unverified, malicious, or broken code directly into production environments.
View full advisory →CVE-2026-21759 published: HCL Hive is affected by an information exposure vulnerability where Swagger documentation was found exposed publicly. Although no sensitive information (e.g., credentials, PII) was discovered, exposing API documentation to unauthenticated users can increas...
View full advisory →CVE-2026-28190 published: Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
View full advisory →CVE-2026-32471 published: Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.
View full advisory →CVE-2026-32476 published: Unauthenticated Cross Site Scripting (XSS) in Brave Conversion Engine (PRO) <= 0.8.6 versions.
View full advisory →CVE-2026-32477 published: Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
View full advisory →CVE-2026-32478 published: Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
View full advisory →CVE-2026-32551 published: Unauthenticated SQL Injection in Woo Essential <= 4.3.0 versions.
View full advisory →CVE-2026-28151 published: Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
View full advisory →CVE-2026-28152 published: Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
View full advisory →CVE-2026-28153 published: Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
View full advisory →CVE-2026-28162 published: Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
View full advisory →CVE-2026-28165 published: Unauthenticated Privilege Escalation in Digits <= 9.2 versions.
View full advisory →CVE-2026-28166 published: Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
View full advisory →CVE-2026-28167 published: Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
View full advisory →CVE-2026-28171 published: Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
View full advisory →