The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2024-13461 - The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 due to insuf... read CVE-2024-13461
Published: February 21, 2025; 5:15:10 AM -0500V3.1: 5.4 MEDIUM
-
CVE-2026-17346 - The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr... read CVE-2026-17346
Published: July 31, 2026; 12:16:58 PM -0400 -
CVE-2026-11536 - IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.
Published: July 30, 2026; 4:16:52 PM -0400 -
CVE-2026-10695 - IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
Published: July 30, 2026; 3:17:01 PM -0400V3.1: 5.5 MEDIUM
-
CVE-2026-62927 - In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by ba... read CVE-2026-62927
Published: August 04, 2026; 9:18:55 AM -0400V3.1: 7.5 HIGH
-
CVE-2026-10535 - IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
Published: July 30, 2026; 3:17:01 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-65891 - Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated u... read CVE-2026-65891
Published: July 29, 2026; 9:19:10 AM -0400 -
CVE-2026-58080 - In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs a... read CVE-2026-58080
Published: August 04, 2026; 9:18:55 AM -0400V3.1: 8.2 HIGH
-
CVE-2026-24033 - Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3, from 9.0.0 through 9.2.14. Users are recommended to up... read CVE-2026-24033
Published: July 29, 2026; 4:16:30 AM -0400V3.1: 5.3 MEDIUM
-
CVE-2026-22068 - Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes... read CVE-2026-22068
Published: July 29, 2026; 4:16:30 AM -0400V3.1: 5.3 MEDIUM
-
CVE-2026-60007 - In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encr... read CVE-2026-60007
Published: August 04, 2026; 9:18:55 AM -0400V3.1: 7.4 HIGH
-
CVE-2026-17348 - In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without th... read CVE-2026-17348
Published: July 31, 2026; 12:16:59 PM -0400 -
CVE-2026-61387 - In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateM... read CVE-2026-61387
Published: August 04, 2026; 9:18:55 AM -0400V3.1: 7.5 HIGH
-
CVE-2026-17349 - /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh... read CVE-2026-17349
Published: July 31, 2026; 12:16:59 PM -0400 -
CVE-2026-17350 - The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but ... read CVE-2026-17350
Published: July 31, 2026; 12:16:59 PM -0400 -
CVE-2026-17351 - The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ... read CVE-2026-17351
Published: July 31, 2026; 12:16:59 PM -0400V3.1: 9.0 CRITICAL
-
CVE-2026-17566 - pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra... read CVE-2026-17566
Published: July 31, 2026; 12:17:00 PM -0400 -
CVE-2026-15325 - IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request smuggling due to improper handling of TRACE requests.
Published: July 28, 2026; 5:17:27 PM -0400 -
CVE-2026-15280 - IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability in the collective routing mechanism.
Published: July 28, 2026; 5:17:27 PM -0400 -
CVE-2026-15064 - IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response Smuggling due to improper handling of non-standard HTTP version tokens.
Published: July 28, 2026; 5:17:27 PM -0400