Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26897
Total
1982
Critical
8080
High
8318
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-6479 | HIGH | 7.5 | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. … | May 14, 2026 |
| CVE-2026-6478 | MEDIUM | 6.5 | Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect … | May 14, 2026 |
| CVE-2026-6477 | HIGH | 8.8 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client … | May 14, 2026 |
| CVE-2026-6476 | HIGH | 7.2 | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser. The attack takes effect when pg_createsubscriber next … | May 14, 2026 |
| CVE-2026-6475 | HIGH | 8.8 | Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system … | May 14, 2026 |
| CVE-2026-6474 | MEDIUM | 4.3 | Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, … | May 14, 2026 |
| CVE-2026-6473 | HIGH | 8.8 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may … | May 14, 2026 |
| CVE-2026-6472 | MEDIUM | 5.4 | Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types. That … | May 14, 2026 |
| CVE-2026-1630 | UNKNOWN | — | WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when … | May 14, 2026 |
| CVE-2025-15025 | HIGH | 8.8 | Authorization bypass through User-Controlled key vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploitation of … | May 14, 2026 |
| CVE-2026-6008 | MEDIUM | 6.8 | Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue … | May 14, 2026 |
| CVE-2026-5798 | UNKNOWN | — | Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker … | May 14, 2026 |
| CVE-2026-5790 | UNKNOWN | — | Stored Cross-Site Scripting (XSS) in Stel Order v3.25.1 and earlier, located at the ‘/app/FrontController’ endpoint via the ‘legalName’ and ‘employeeID’ parameters. The lack of proper … | May 14, 2026 |
| CVE-2026-4031 | HIGH | 7.5 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.2. This is due to … | May 14, 2026 |
| CVE-2026-4030 | HIGH | 8.1 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized arbitrary file read and deletion in all versions up to, and including, 2.5.2. … | May 14, 2026 |
| CVE-2026-4029 | HIGH | 7.5 | The Database Backup for WordPress plugin for WordPress is vulnerable to unauthorized database export in all versions up to, and including, 2.5.2. This is due … | May 14, 2026 |
| CVE-2026-43644 | MEDIUM | 5.4 | podinfo through 6.11.2 contains a reflected cross-site scripting vulnerability in the /echo and /api/echo endpoints where the echoHandler writes request body content directly to the … | May 14, 2026 |
| CVE-2025-12008 | HIGH | 8.8 | Authorization bypass through User-Controlled key vulnerability in APPYAP Technology and Information Inc. Yaay Social Media App allows Accessing Functionality Not Properly Constrained by ACLs. This … | May 14, 2026 |
| CVE-2026-45205 | MEDIUM | 5.3 | Uncontrolled Recursion vulnerability in Apache Commons. When processing an untrusted configuration file, Commons Configuration will throw a StackOverflowError for YAML input with cycles. This issue … | May 14, 2026 |
| CVE-2026-8468 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in plug_project plug allows denial of service via unbounded buffer accumulation in multipart header parsing. 'Elixir.Plug.Conn':read_part_headers/2 in … | May 14, 2026 |
| CVE-2026-8295 | UNKNOWN | — | An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on platforms with … | May 14, 2026 |
| CVE-2025-68421 | UNKNOWN | — | Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote … | May 14, 2026 |
| CVE-2025-68420 | UNKNOWN | — | Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It … | May 14, 2026 |
| CVE-2026-2347 | CRITICAL | 9.8 | Authorization bypass through User-Controlled key vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Session Hijacking. This issue affects E-Commerce Website: before 4.5.001. | May 14, 2026 |
| CVE-2025-11024 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows Blind SQL … | May 14, 2026 |