Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51620
Total
4095
Critical
15305
High
14964
Medium
CVE ID Severity Score Description Published
CVE-2026-45813 HIGH 8.8 Out-of-bounds Write, Integer Underflow (Wrap or Wraparound) vulnerability in Apache NimBLE BASS service. Improper validation when parsing BASS service "Add Source" and "Modify Source" operation … Jul 24, 2026
CVE-2026-45812 MEDIUM 6.5 Incorrect Calculation of Buffer Size vulnerability in Apache NimBLE when processing Legacy Advertising Report HCI event. When a single HCI advertising report event bundles multiple … Jul 24, 2026
CVE-2026-45811 HIGH 7.5 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Apache NimBLE. The HCI socket transport did not check whether a received HCI … Jul 24, 2026
CVE-2026-16743 MEDIUM 5.5 A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and privilege drop performed … Jul 24, 2026
CVE-2026-16730 MEDIUM 5.5 A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, … Jul 24, 2026
CVE-2026-15810 UNKNOWN — A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28, and 26.8.7 on Looker-hosted and Self-hosted … Jul 24, 2026
CVE-2026-15243 UNKNOWN — Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker … Jul 24, 2026
CVE-2026-10610 UNKNOWN — Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user. Jul 24, 2026
CVE-2026-7483 UNKNOWN — Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user. Jul 24, 2026
CVE-2026-16634 UNKNOWN — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has an uncontrolled … Jul 24, 2026
CVE-2026-15663 MEDIUM 4.9 The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings' … Jul 24, 2026
CVE-2026-15401 HIGH 7.2 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions up to, … Jul 24, 2026
CVE-2026-10033 HIGH 7.3 The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the … Jul 24, 2026
CVE-2026-63317 MEDIUM 5.6 Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3.0.0-M5 Description: Three code … Jul 24, 2026
CVE-2026-56392 UNKNOWN — GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. … Jul 24, 2026
CVE-2026-56391 UNKNOWN — GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() … Jul 24, 2026
CVE-2026-49745 HIGH 7.8 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the … Jul 24, 2026
CVE-2026-49744 HIGH 7.8 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the … Jul 24, 2026
CVE-2026-49743 HIGH 7.8 Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in the kernel, leading … Jul 24, 2026
CVE-2026-24727 UNKNOWN — An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote … Jul 24, 2026
CVE-2026-15821 MEDIUM 6.4 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, … Jul 24, 2026
CVE-2026-15739 MEDIUM 6.4 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all versions up to, and … Jul 24, 2026
CVE-2026-15704 CRITICAL 9.8 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between … Jul 24, 2026
CVE-2026-15346 MEDIUM 6.1 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all versions up to, … Jul 24, 2026
CVE-2026-12702 UNKNOWN — In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. Jul 24, 2026