Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51667
Total
4097
Critical
15338
High
14987
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59676 | UNKNOWN | — | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain … | Jul 23, 2026 |
| CVE-2026-14291 | HIGH | 7.5 | The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker … | Jul 23, 2026 |
| CVE-2026-12082 | HIGH | 7.5 | The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify … | Jul 23, 2026 |
| CVE-2026-7534 | HIGH | 7.2 | The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and … | Jul 23, 2026 |
| CVE-2026-7232 | HIGH | 7.2 | The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due … | Jul 23, 2026 |
| CVE-2026-64600 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an … | Jul 23, 2026 |
| CVE-2026-63226 | MEDIUM | 5.8 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When … | Jul 23, 2026 |
| CVE-2026-6390 | MEDIUM | 6.8 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, … | Jul 23, 2026 |
| CVE-2026-7120 | MEDIUM | 5.3 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including … | Jul 23, 2026 |
| CVE-2026-15074 | HIGH | 7.5 | @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of … | Jul 23, 2026 |
| CVE-2026-21723 | MEDIUM | 5.3 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana … | Jul 23, 2026 |
| CVE-2026-16653 | MEDIUM | 5.3 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public … | Jul 23, 2026 |
| CVE-2026-16632 | HIGH | 7.3 | A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/websocket_parser.h of the component WebSocket Frame … | Jul 23, 2026 |
| CVE-2026-16631 | MEDIUM | 5.3 | A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The … | Jul 23, 2026 |
| CVE-2026-61246 | HIGH | 8.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60455 | HIGH | 8.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60439 | HIGH | 8.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60373 | HIGH | 8.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60372 | CRITICAL | 9.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60371 | HIGH | 8.0 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60370 | HIGH | 7.5 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60369 | CRITICAL | 9.9 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60368 | HIGH | 8.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60367 | CRITICAL | 9.8 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |
| CVE-2026-60366 | CRITICAL | 10.0 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and … | Jul 22, 2026 |