Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-57721

WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability_CVE-2026-57721

Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue...

WP Reloaded ApplyOnline n/a CVE
MEDIUM 4.3 CVE-2026-57720

WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability_CVE-2026-57720

Missing Authorization vulnerability in Codexpert Inc ThumbPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issu...

Codexpert Inc ThumbPress n/a CVE
HIGH 8.6 CVE-2026-57516

Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader_CVE-2026-57516

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code executio...

Anyscale, Inc Ray CVE
MEDIUM 5.3 CVE-2026-56152

Incorrect Authorization in Elastic Defend Leading to Information Disclosure_CVE-2026-56152

Incorrect Authorization (CWE-863) in Elastic Defend can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constr...

Elastic Elastic Defend 9.3.0 CVE
MEDIUM 6.5 CVE-2026-56151

Improper Input Validation in Kibana Leading to Denial of Service_CVE-2026-56151

Improper Input Validation (CWE-20) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authenticated user can sub...

Elastic Kibana 9.0.0 CVE
MEDIUM 6.5 CVE-2026-56150

Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service_CVE-2026-56150

Allocation of Resources Without Limits or Throttling (CWE-770) in Fleet Server can lead to a denial of service via Excessive Allocation (CAPEC-130)...

Elastic Fleet Server 9.0.0 CVE
MEDIUM 4.9 CVE-2026-56149

Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service_CVE-2026-56149

Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130...

Elastic Elasticsearch 9.4.0 CVE
MEDIUM 6.5 CVE-2026-56148

Uncontrolled Recursion in Elasticsearch Leading to Denial of Service_CVE-2026-56148

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can s...

Elastic Elasticsearch 9.4.0 CVE
HIGH 7.5 CVE-2026-54399

Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration_CVE-2026-54399

Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earl...

Apache Software Foundation Apache HttpComponents Core 5.5-alpha CVE
MEDIUM 4.4 CVE-2026-49088

Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure_CVE-2026-49088

Insertion of Sensitive Information into Log File (CWE-532) in Kibana can lead to information disclosure. When the optional application performance ...

Elastic Kibana 8.0.0 CVE