Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51605
Total
4093
Critical
15302
High
14954
Medium
CVE ID Severity Score Description Published
CVE-2026-16766 UNKNOWN — Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options. Options are passed directly to the wkhtmltopdf command without sanitization. … Jul 25, 2026
CVE-2026-15425 MEDIUM 6.4 The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) … Jul 25, 2026
CVE-2026-14955 MEDIUM 6.5 The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7 via the … Jul 25, 2026
CVE-2026-10818 HIGH 8.1 The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.10.1.1 via the ajax_chunk_upload_finalize function. This … Jul 25, 2026
CVE-2026-66374 HIGH 8.1 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path. Jul 25, 2026
CVE-2026-66373 HIGH 7.5 Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same … Jul 25, 2026
CVE-2026-66339 MEDIUM 6.5 A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS … Jul 24, 2026
CVE-2026-66338 MEDIUM 5.4 A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC … Jul 24, 2026
CVE-2026-66337 MEDIUM 6.5 A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A … Jul 24, 2026
CVE-2026-61892 HIGH 8.8 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. Jul 24, 2026
CVE-2026-61886 MEDIUM 6.5 Weintek cMT3092X HMI stores user account passwords in plaintext. Jul 24, 2026
CVE-2026-60135 MEDIUM 6.5 An attacker can modify data that should be restricted to read‑only access. Jul 24, 2026
CVE-2026-60134 HIGH 8.8 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. Jul 24, 2026
CVE-2026-16280 UNKNOWN — An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This … Jul 24, 2026
CVE-2026-61884 CRITICAL 9.8 The web management interface of Tycon Systems TPDIN-Monitor-WEB2 does not perform server-side validation of credentials during the login process. By submitting empty values for both … Jul 24, 2026
CVE-2026-55985 MEDIUM 4.3 The web management interface in Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any … Jul 24, 2026
CVE-2025-71408 HIGH 7.8 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations module that allows an attacker who controls command-line arguments to … Jul 24, 2026
CVE-2026-66041 HIGH 8.8 FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap … Jul 24, 2026
CVE-2026-66040 HIGH 8.8 FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to … Jul 24, 2026
CVE-2026-66039 HIGH 8.8 FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory … Jul 24, 2026
CVE-2026-66038 MEDIUM 6.5 FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory … Jul 24, 2026
CVE-2026-66037 MEDIUM 6.5 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte … Jul 24, 2026
CVE-2026-66036 HIGH 8.8 FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by … Jul 24, 2026
CVE-2026-62835 CRITICAL 9.3 Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. Jul 24, 2026
CVE-2026-57531 MEDIUM 5.4 Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScript in the host application's … Jul 24, 2026