Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51605
Total
4093
Critical
15302
High
14954
Medium
CVE ID Severity Score Description Published
CVE-2026-12394 CRITICAL 9.8 The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary … Jul 27, 2026
CVE-2026-12255 HIGH 8.1 The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for … Jul 27, 2026
CVE-2026-10082 MEDIUM 6.1 The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the … Jul 27, 2026
CVE-2025-15662 HIGH 8.6 The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does … Jul 27, 2026
CVE-2026-15928 UNKNOWN — XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. Jul 27, 2026
CVE-2026-17501 MEDIUM 5.3 A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This … Jul 27, 2026
CVE-2026-17500 MEDIUM 5.3 A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The … Jul 27, 2026
CVE-2026-57990 HIGH 7.4 Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Jul 26, 2026
CVE-2026-57989 HIGH 7.4 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Jul 26, 2026
CVE-2026-57978 MEDIUM 5.4 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Jul 26, 2026
CVE-2026-17497 HIGH 8.3 NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running … Jul 26, 2026
CVE-2026-17496 HIGH 8.1 NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML … Jul 26, 2026
CVE-2026-17459 MEDIUM 4.3 A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing … Jul 26, 2026
CVE-2026-17458 MEDIUM 6.3 A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP … Jul 26, 2026
CVE-2026-17457 MEDIUM 4.3 A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the … Jul 26, 2026
CVE-2026-64530 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held … Jul 26, 2026
CVE-2024-14040 UNKNOWN — In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various … Jul 26, 2026
CVE-2026-63720 HIGH 7.5 datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a … Jul 26, 2026
CVE-2026-17434 MEDIUM 6.3 A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing … Jul 26, 2026
CVE-2026-17433 MEDIUM 5.3 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. … Jul 26, 2026
CVE-2026-15962 HIGH 8.8 The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via … Jul 26, 2026
CVE-2026-17432 MEDIUM 5.0 A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway … Jul 26, 2026
CVE-2026-10681 MEDIUM 6.5 In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, … Jul 25, 2026
CVE-2026-66013 UNKNOWN — OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a … Jul 25, 2026
CVE-2026-66012 CRITICAL 10.0 SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with … Jul 25, 2026