Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-45709 MEDIUM 5.8 Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in … Jul 20, 2026
CVE-2026-35198 CRITICAL 9.0 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member … Jul 20, 2026
CVE-2026-32822 MEDIUM 6.1 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … Jul 20, 2026
CVE-2026-32807 HIGH 7.5 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, … Jul 20, 2026
CVE-2026-28220 HIGH 8.4 Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API … Jul 20, 2026
CVE-2026-27823 UNKNOWN — A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands … Jul 20, 2026
CVE-2026-26199 UNKNOWN — HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with … Jul 20, 2026
CVE-2026-26197 UNKNOWN — HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array … Jul 20, 2026
CVE-2026-26081 MEDIUM 4.8 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected. Jul 20, 2026
CVE-2026-26080 LOW 3.7 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected. Jul 20, 2026
CVE-2026-25039 HIGH 8.8 Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that … Jul 20, 2026
CVE-2026-21824 HIGH 8.8 HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations. Jul 20, 2026
CVE-2026-13724 MEDIUM 4.3 Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This … Jul 20, 2026
CVE-2026-63091 MEDIUM 6.5 ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass … Jul 20, 2026
CVE-2026-63090 HIGH 8.8 ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that allows authenticated low-privilege attackers to achieve arbitrary code execution … Jul 20, 2026
CVE-2026-63071 UNKNOWN — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing … Jul 20, 2026
CVE-2026-62418 UNKNOWN — Low-privileged authenticated Server-Side Request Forgery (SSRF) vulnerability in Apache Syncope via Connectors and Resources check. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from … Jul 20, 2026
CVE-2026-62183 UNKNOWN — Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user workflow adapter is configured, … Jul 20, 2026
CVE-2026-59238 UNKNOWN — Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview, renderEditor, renderAuditData in js/app.js) in maalfer Pentestify before 1.1.0 allows a remote, authenticated attacker … Jul 20, 2026
CVE-2026-57308 UNKNOWN — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of … Jul 20, 2026
CVE-2026-54910 HIGH 7.7 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and … Jul 20, 2026
CVE-2026-54685 MEDIUM 5.3 FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a … Jul 20, 2026
CVE-2026-53421 UNKNOWN — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on … Jul 20, 2026
CVE-2026-53405 UNKNOWN — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then … Jul 20, 2026
CVE-2026-52349 UNKNOWN — Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner … Jul 20, 2026