CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-21754 MEDIUM

CVE-2026-21754 published: HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.

View full advisory →
CVE-2026-21758 LOW

CVE-2026-21758 published: HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.

View full advisory →
CVE-2026-12600 UNKNOWN

CVE-2026-12600 published: Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker...

View full advisory →
CVE-2026-75037 HIGH

CVE-2026-75037 published: Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.

View full advisory →
CVE-2026-75038 MEDIUM

CVE-2026-75038 published: UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.

View full advisory →
CVE-2026-76128 MEDIUM

CVE-2026-76128 published: The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible f...

View full advisory →
CVE-2026-78570 CRITICAL

CVE-2026-78570 published: The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of an adminsitrator.

View full advisory →
CVE-2026-78572 HIGH

CVE-2026-78572 published: The Kalles Addons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.6 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain ...

View full advisory →
CVE-2026-78576 HIGH

CVE-2026-78576 published: The Readabler plugin for WordPress is vulnerable to SQL Injection in all versions up to 2.0.18 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for ...

View full advisory →
CVE-2026-49050 HIGH

CVE-2026-49050 published: General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

View full advisory →
CVE-2026-16231 HIGH

CVE-2026-16231 published: hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeh...

View full advisory →
CVE-2026-12878 UNKNOWN

CVE-2026-12878 published: In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

View full advisory →
CVE-2026-77128 UNKNOWN

CVE-2026-77128 published: The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active...

View full advisory →
CVE-2026-77129 UNKNOWN

CVE-2026-77129 published: The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose se...

View full advisory →
CVE-2026-77130 UNKNOWN

CVE-2026-77130 published: The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY projec...

View full advisory →
CVE-2026-77131 UNKNOWN

CVE-2026-77131 published: When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

View full advisory →
CVE-2026-77133 UNKNOWN

CVE-2026-77133 published: The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.

View full advisory →
CVE-2026-77134 UNKNOWN

CVE-2026-77134 published: The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pe...

View full advisory →
CVE-2026-63587 HIGH

CVE-2026-63587 published: The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS ...

View full advisory →
CVE-2026-77127 UNKNOWN

CVE-2026-77127 published: The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error re...

View full advisory →