Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53594 | MEDIUM | 4.9 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled … | Jul 20, 2026 |
| CVE-2026-47198 | HIGH | 8.5 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, … | Jul 20, 2026 |
| CVE-2026-47130 | HIGH | 7.1 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact … | Jul 20, 2026 |
| CVE-2026-47129 | HIGH | 8.1 | NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js … | Jul 20, 2026 |
| CVE-2026-44585 | MEDIUM | 5.4 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied … | Jul 20, 2026 |
| CVE-2026-44584 | MEDIUM | 4.3 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate … | Jul 20, 2026 |
| CVE-2026-44583 | MEDIUM | 5.3 | Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the … | Jul 20, 2026 |
| CVE-2026-44509 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users … | Jul 20, 2026 |
| CVE-2026-44508 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users … | Jul 20, 2026 |
| CVE-2026-44507 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a duplicate of CVE-2026-43617. Notes: All CVE users … | Jul 20, 2026 |
| CVE-2026-13381 | UNKNOWN | — | VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' … | Jul 20, 2026 |
| CVE-2026-13380 | UNKNOWN | — | VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in … | Jul 20, 2026 |
| CVE-2024-51313 | CRITICAL | 9.8 | The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. | Jul 20, 2026 |
| CVE-2024-51311 | CRITICAL | 9.8 | The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. | Jul 20, 2026 |
| CVE-2026-63767 | CRITICAL | 9.8 | ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle … | Jul 20, 2026 |
| CVE-2026-63766 | CRITICAL | 9.8 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into … | Jul 20, 2026 |
| CVE-2026-53593 | HIGH | 8.8 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads … | Jul 20, 2026 |
| CVE-2026-53592 | MEDIUM | 4.6 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was … | Jul 20, 2026 |
| CVE-2026-53591 | HIGH | 8.6 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into … | Jul 20, 2026 |
| CVE-2026-44231 | CRITICAL | 9.1 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure … | Jul 20, 2026 |
| CVE-2026-44230 | MEDIUM | 6.1 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not … | Jul 20, 2026 |
| CVE-2026-44229 | MEDIUM | 5.4 | RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a … | Jul 20, 2026 |
| CVE-2026-16337 | UNKNOWN | — | Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to … | Jul 20, 2026 |
| CVE-2026-15788 | UNKNOWN | — | BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build … | Jul 20, 2026 |
| CVE-2026-64619 | HIGH | 7.5 | FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and … | Jul 20, 2026 |