CVE watch

Every disclosure pulled from the NVD feed, filterable by severity.

All Critical High Medium Low Unknown
CVE-2026-56094 UNKNOWN

CVE-2026-56094 published: The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core se...

View full advisory →
CVE-2026-56095 UNKNOWN

CVE-2026-56095 published: The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a ...

View full advisory →
CVE-2026-56096 UNKNOWN

CVE-2026-56096 published: The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed fie...

View full advisory →
CVE-2026-63586 CRITICAL

CVE-2026-63586 published: The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the syst...

View full advisory →
CVE-2026-56093 UNKNOWN

CVE-2026-56093 published: The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through ...

View full advisory →
CVE-2026-17548 UNKNOWN

CVE-2026-17548 published: Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

View full advisory →
CVE-2026-56092 UNKNOWN

CVE-2026-56092 published: The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherite...

View full advisory →
CVE-2026-66882 UNKNOWN

CVE-2026-66882 published: Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured with require_intera...

View full advisory →
CVE-2026-67578 HIGH

CVE-2026-67578 published: FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.

View full advisory →
CVE-2026-78322 MEDIUM

CVE-2026-78322 published: A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string cop...

View full advisory →
CVE-2026-78701 MEDIUM

CVE-2026-78701 published: A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, lead...

View full advisory →
CVE-2026-59769 CRITICAL

CVE-2026-59769 published: FA-50 all versions contain hard-coded credentials. An attacker, who knows the credentials and has access to the vessel's internal network, can operate the settings screen using that credentials to alter the identification number.

View full advisory →
CVE-2026-65633 UNKNOWN

CVE-2026-65633 published: Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as full bearer API credentials when a resource uses stateless bearer-token verification. The bearer-token authentication helper AshAuthentica...

View full advisory →
CVE-2026-16601 HIGH

CVE-2026-16601 published: The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is vulnerable to Limited Arbitrary File Upload in all versions up to, and including, 2.1.8 via the uploadMedia function. This is due to insufficient file type val...

View full advisory →
CVE-2026-18100 MEDIUM

CVE-2026-18100 published: The MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'mf_form_id' Widget Setting in all versions up to, and including, 4.1.8 due to insufficient input sanitizatio...

View full advisory →
CVE-2026-18323 HIGH

CVE-2026-18323 published: The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sani...

View full advisory →
CVE-2026-18328 HIGH

CVE-2026-18328 published: The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient inp...

View full advisory →
CVE-2026-18512 MEDIUM

CVE-2026-18512 published: The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Approved Comment Body Rendered in Translation Editor Strings Dropdown in all versions up to, and including, 3.2.6 due...

View full advisory →
CVE-2026-19851 HIGH

CVE-2026-19851 published: A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.

View full advisory →
CVE-2026-66109 HIGH

CVE-2026-66109 published: A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM ...

View full advisory →