Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26897
Total
1982
Critical
8080
High
8318
Medium
CVE ID Severity Score Description Published
CVE-2026-6479 HIGH 7.5 Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. … May 14, 2026
CVE-2026-6478 MEDIUM 6.5 Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect … May 14, 2026
CVE-2026-6477 HIGH 8.8 Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client … May 14, 2026
CVE-2026-6476 HIGH 7.2 SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next … May 14, 2026
CVE-2026-6475 HIGH 8.8 Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system … May 14, 2026
CVE-2026-6474 MEDIUM 4.3 Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, … May 14, 2026
CVE-2026-6473 HIGH 8.8 Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may … May 14, 2026
CVE-2026-6472 MEDIUM 5.4 Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That … May 14, 2026
CVE-2026-1630 UNKNOWN WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when … May 14, 2026
CVE-2025-15025 HIGH 8.8 Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploitation of … May 14, 2026
CVE-2026-6008 MEDIUM 6.8 Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue … May 14, 2026
CVE-2026-5798 UNKNOWN Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker … May 14, 2026
CVE-2026-5790 UNKNOWN Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper … May 14, 2026
CVE-2026-4031 HIGH 7.5 The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to … May 14, 2026
CVE-2026-4030 HIGH 8.1 The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. … May 14, 2026
CVE-2026-4029 HIGH 7.5 The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due … May 14, 2026
CVE-2026-43644 MEDIUM 5.4 podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the … May 14, 2026
CVE-2025-12008 HIGH 8.8 Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This … May 14, 2026
CVE-2026-45205 MEDIUM 5.3 Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue … May 14, 2026
CVE-2026-8468 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in … May 14, 2026
CVE-2026-8295 UNKNOWN An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on platforms with … May 14, 2026
CVE-2025-68421 UNKNOWN Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote … May 14, 2026
CVE-2025-68420 UNKNOWN Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It … May 14, 2026
CVE-2026-2347 CRITICAL 9.8 Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001. May 14, 2026
CVE-2025-11024 CRITICAL 9.8 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL … May 14, 2026