CVE watch
Every disclosure pulled from the NVD feed, filterable by severity.
CVE-2026-45404 published: OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's bridgeSpan contains an unsynchronized extraBaggageItems map which can cause a panic. Because Go maps are not safe for concurrent read/wr...
View full advisory →CVE-2026-32560 published: Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions.
View full advisory →CVE-2026-32561 published: Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
View full advisory →CVE-2026-32563 published: Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
View full advisory →CVE-2026-27364 published: Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.
View full advisory →CVE-2026-32554 published: Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
View full advisory →CVE-2026-32555 published: Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
View full advisory →CVE-2026-32556 published: Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
View full advisory →CVE-2026-32559 published: Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
View full advisory →CVE-2026-17113 published: A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI `Envs` ...
View full advisory →CVE-2026-77567 published: Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are e...
View full advisory →CVE-2026-75464 published: OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link().
View full advisory →CVE-2026-75542 published: Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. When an API key is exchanged for a token through the OAuth client_creden...
View full advisory →CVE-2026-75554 published: Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private packages. expand_repositories_scope/3 in lib/hexpm/permissions.ex only rewrites the literal...
View full advisory →CVE-2026-5006 published: A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated policy path to gain unintended access to Vault paths. An attacker who can contro...
View full advisory →CVE-2026-56135 published: In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting a malicious NTFS image. The overflow i...
View full advisory →CVE-2026-56136 published: In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process by crafting a malicious NTFS image. This read operation is triggered b...
View full advisory →CVE-2026-55468 published: Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the internal Pages admin API returns page fields declared in api_fields without sufficient access contr...
View full advisory →CVE-2026-52490 published: An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
View full advisory →CVE-2026-52492 published: An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image
View full advisory →