Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51605
Total
4093
Critical
15302
High
14954
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12394 | CRITICAL | 9.8 | The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary … | Jul 27, 2026 |
| CVE-2026-12255 | HIGH | 8.1 | The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for … | Jul 27, 2026 |
| CVE-2026-10082 | MEDIUM | 6.1 | The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode parameter before outputting it in the page, allowing users with the … | Jul 27, 2026 |
| CVE-2025-15662 | HIGH | 8.6 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does … | Jul 27, 2026 |
| CVE-2026-15928 | UNKNOWN | — | XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. | Jul 27, 2026 |
| CVE-2026-17501 | MEDIUM | 5.3 | A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerability affects the function transform of the file common/json-schema-to-grammar.cpp of the component JSON-Schema-to-GBNF Conversion. This … | Jul 27, 2026 |
| CVE-2026-17500 | MEDIUM | 5.3 | A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The … | Jul 27, 2026 |
| CVE-2026-57990 | HIGH | 7.4 | Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | Jul 26, 2026 |
| CVE-2026-57989 | HIGH | 7.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | Jul 26, 2026 |
| CVE-2026-57978 | MEDIUM | 5.4 | Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | Jul 26, 2026 |
| CVE-2026-17497 | HIGH | 8.3 | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running … | Jul 26, 2026 |
| CVE-2026-17496 | HIGH | 8.1 | NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML … | Jul 26, 2026 |
| CVE-2026-17459 | MEDIUM | 4.3 | A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing … | Jul 26, 2026 |
| CVE-2026-17458 | MEDIUM | 6.3 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP … | Jul 26, 2026 |
| CVE-2026-17457 | MEDIUM | 4.3 | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserNavigationAllowed of the file src/browser/navigation-guard.ts of the … | Jul 26, 2026 |
| CVE-2026-64530 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held … | Jul 26, 2026 |
| CVE-2024-14040 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: nexthop: Increase weight to u16 In CLOS networks, as link failures occur at various … | Jul 26, 2026 |
| CVE-2026-63720 | HIGH | 7.5 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a … | Jul 26, 2026 |
| CVE-2026-17434 | MEDIUM | 6.3 | A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing … | Jul 26, 2026 |
| CVE-2026-17433 | MEDIUM | 5.3 | A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk-bridge.ts of the component MCP Server Approval. … | Jul 26, 2026 |
| CVE-2026-15962 | HIGH | 8.8 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via … | Jul 26, 2026 |
| CVE-2026-17432 | MEDIUM | 5.0 | A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway … | Jul 26, 2026 |
| CVE-2026-10681 | MEDIUM | 6.5 | In Zephyr's userspace dynamic-objects subsystem, thread_idx_alloc() in kernel/userspace/userspace.c allocated a new thread permission index from the global _thread_idx_map[] bitmap without holding lists_lock. On SMP systems, … | Jul 25, 2026 |
| CVE-2026-66013 | UNKNOWN | — | OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a … | Jul 25, 2026 |
| CVE-2026-66012 | CRITICAL | 10.0 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with … | Jul 25, 2026 |