CVE Vulnerability Database

Complete database of CVE vulnerabilities. Track critical security threats, exploits and patches. Updated daily from NVD NIST.

CVE-2026-62103

9.8

Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

PHP
Details

CVE-2026-62102

8.8

Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

Subscriber
Details

CVE-2026-62089

7.1

Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

Details

CVE-2026-62088

5.3

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

Insertion
Details

CVE-2026-54072

9.3

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server …

Meta
Details

CVE-2026-27378

5.3

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Details

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to …

Linkstack
Details

CVE-2026-9160

4.3

Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The …

Details

CVE-2026-89099

7.7

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An …

MongoDB
Details

CVE-2026-89090

8.2

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process …

Amazon
Details
61/8691