Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52656 | CRITICAL | 9.8 | An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via … | Jul 20, 2026 |
| CVE-2026-51385 | MEDIUM | 6.9 | An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary … | Jul 20, 2026 |
| CVE-2026-51031 | HIGH | 7.5 | FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information | Jul 20, 2026 |
| CVE-2026-51025 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file | Jul 20, 2026 |
| CVE-2026-47255 | HIGH | 8.2 | AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0.9.10 had weakness related to … | Jul 20, 2026 |
| CVE-2026-47144 | MEDIUM | 5.5 | Shamefile is a linter for undocumented linter warnings. Prior to version 0.1.7, a path traversal vulnerability in `shame next` allows an attacker-controlled `shamefile.yaml` to disclose … | Jul 20, 2026 |
| CVE-2026-47134 | UNKNOWN | — | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk policy database (`/Library/Application Support/clearancekit/store.db`) … | Jul 20, 2026 |
| CVE-2026-47133 | UNKNOWN | — | ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-disk SQLite policy store (`/Library/Application … | Jul 20, 2026 |
| CVE-2026-47128 | MEDIUM | 6.1 | nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow access to … | Jul 20, 2026 |
| CVE-2026-44510 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users … | Jul 20, 2026 |
| CVE-2026-16324 | HIGH | 7.3 | A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qnaire/upload.jsp. Such manipulation … | Jul 20, 2026 |
| CVE-2026-12900 | MEDIUM | 6.4 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/image` block in … | Jul 20, 2026 |
| CVE-2024-51316 | HIGH | 7.5 | The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName | Jul 20, 2026 |
| CVE-2024-51315 | CRITICAL | 9.8 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName | Jul 20, 2026 |
| CVE-2024-51314 | CRITICAL | 9.8 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. | Jul 20, 2026 |
| CVE-2024-51312 | CRITICAL | 9.8 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. | Jul 20, 2026 |
| CVE-2026-64651 | UNKNOWN | — | The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes requests from any process whose command … | Jul 20, 2026 |
| CVE-2026-64650 | UNKNOWN | — | The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to version 1.0.29, the tool relay authorizes … | Jul 20, 2026 |
| CVE-2026-58624 | MEDIUM | 5.4 | Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though … | Jul 20, 2026 |
| CVE-2026-56624 | HIGH | 7.3 | Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation … | Jul 20, 2026 |
| CVE-2026-56623 | HIGH | 7.1 | Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server … | Jul 20, 2026 |
| CVE-2026-56452 | HIGH | 7.5 | Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of … | Jul 20, 2026 |
| CVE-2026-55219 | MEDIUM | 5.3 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes … | Jul 20, 2026 |
| CVE-2026-53596 | MEDIUM | 5.3 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce … | Jul 20, 2026 |
| CVE-2026-53595 | CRITICAL | 9.4 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects … | Jul 20, 2026 |