Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-78604 — Elastic Agent Incorrect Permission Assignment Privilege Escalation

Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is ins…

elastic_agent | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-78602 — Elastic Maps Server Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated at…

Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.5 MEDIUM
CVE-2026-78601 — Kibana Missing Authorization Vulnerability

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation…

kibana | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
3.5 LOW
CVE-2026-78600 — Elastic Cloud on Kubernetes Incomplete Cleanup Privilege Escalation

Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace associati…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-78599 — Kibana Fleet Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAP…

kibana | Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-78598 — Kibana Machine Learning Incorrect Authorization Vulnerability

Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authen…

kibana | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.9 MEDIUM
CVE-2026-78594 — Elastic APM Server Improper Handling of Highly Compressed Data Denial of Service

Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source …

apm_server | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.3 MEDIUM
CVE-2026-78591 — Kibana Fleet Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). …

kibana | Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.3 HIGH
CVE-2026-78590 — Kibana Fleet Path Traversal Vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (C…

kibana | Remote | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-78588 — Filebeat Resource Exhaustion Vulnerability

Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion …

filebeat | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
3.1 LOW
CVE-2026-78587 — Fleet Server Improper Authorization Vulnerability

Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership …

fleet_server | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-78586 — Kibana Memory Exhaustion Denial of Service Vulnerability

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could su…

kibana | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-78584 — Kibana Osquery Information Disclosure Vulnerability

Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-quer…

kibana | Remote | Information Disclosure
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-78153 — Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API R…

The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to byp…

Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-77794 — RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users t…

registrationmagic | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.3 MEDIUM
CVE-2026-77793 — RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field

The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without payi…

registrationmagic | Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.9 CRITICAL
CVE-2026-77009 — WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console

The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to r…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
10.0 CRITICAL
CVE-2026-4357 — Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to …

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-2811 — Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection

The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for un…

Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.5 MEDIUM
CVE-2026-2688 — CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass

The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip non…

Remote | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12567 Results