In Django versions 6.0 before 6.0.7 and 5.2 before 5.2.16 a medium severity vulnerability CVE-2026-53878 was detected. This vulnerability allows for potential header injection attacks. To address this issue, users should upgrade Django to version 5.2.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-53878.
Read more Application DevelopmentIn Website Builder by SeedProd – Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode component for WordPress versions 6.20.2 and earlier a medium severity vulnerability CVE-2025-14785 was detected. This vulnerability allows authenticated attackers to inject arbitrary web scripts. To address this issue, users should upgrade Website Builder by SeedProd – Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14785.
Read more CMSIn Django versions 6.0 before 6.0.7 and 5.2 before 5.2.16 a low severity vulnerability CVE-2026-48588 was detected. This vulnerability allows remote attackers to read private data from the shared cache. To address this issue, users should upgrade Django to version 5.2.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-48588.
Read more Application DevelopmentIn Pillow component for Python versions prior to 12.3.0 a medium severity vulnerability CVE-2026-55798 was detected. This vulnerability allows an attacker to inject arbitrary commands. To address this issue, users should upgrade Pillow to version 12.3.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-55798.
Read more Application DevelopmentIn Terraform a high severity vulnerability CVE-2026-14468 was detected. This vulnerability allows an authenticated user to include files from outside the intended repository content in a module and then download them, potentially exposing sensitive files. To address this issue, users should upgrade Terraform to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-14468.
Read more Developer ToolsIn vLLM versions before 0.24.0 a high severity vulnerability CVE-2026-54234 was detected. This vulnerability allows a remote attacker to crash the engine worker, causing a denial of service. To address this issue, users should upgrade vLLM to version 0.24.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54234.
Read more Machine LearningIn Traefik versions prior to v2.11.51, v3.6.22, and v3.7.6 a critical severity vulnerability CVE-2026-54763 was detected. This vulnerability allows attackers to bypass authentication by using underscore-variant header names. To address this issue, users should upgrade Traefik to version 2.11.51 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-54763.
Read more SecurityIn vLLM versions 0.22.0 to 0.23.0 a medium severity vulnerability CVE-2026-55646 was detected. This vulnerability allows an attacker to cause a denial of service through memory exhaustion by uploading an oversized audio file. To address this issue, users should upgrade vLLM to version 0.24.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-55646.
Read more Machine LearningIn FileOrganizer component for WordPress versions before 1.2.0 a high severity vulnerability CVE-2026-11962 was detected. This vulnerability allows an authenticated attacker to achieve remote code execution. To address this issue, users should upgrade FileOrganizer to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-11962.
Read more CMS