Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51763
Total
4101
Critical
15352
High
15010
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51386 | UNKNOWN | — | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate of CVE-2026-46409. Notes: All CVE users should reference … | Jul 20, 2026 |
| CVE-2026-46516 | UNKNOWN | — | Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js/chat.js`'s `formatMarkdown`) inserted regex capture groups as raw HTML in four template … | Jul 20, 2026 |
| CVE-2026-46410 | UNKNOWN | — | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. … | Jul 20, 2026 |
| CVE-2026-45270 | HIGH | 8.7 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page … | Jul 20, 2026 |
| CVE-2026-45139 | MEDIUM | 6.5 | CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, … | Jul 20, 2026 |
| CVE-2026-16277 | MEDIUM | 6.5 | A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server … | Jul 20, 2026 |
| CVE-2026-16252 | HIGH | 7.3 | A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file … | Jul 20, 2026 |
| CVE-2026-12701 | CRITICAL | 9.0 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block … | Jul 20, 2026 |
| CVE-2026-57311 | UNKNOWN | — | Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. … | Jul 20, 2026 |
| CVE-2026-57310 | UNKNOWN | — | Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash … | Jul 20, 2026 |
| CVE-2026-57309 | UNKNOWN | — | A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in … | Jul 20, 2026 |
| CVE-2026-16248 | HIGH | 8.8 | A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of … | Jul 20, 2026 |
| CVE-2026-16244 | MEDIUM | 6.3 | A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such … | Jul 20, 2026 |
| CVE-2026-12080 | HIGH | 7.3 | A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating … | Jul 20, 2026 |
| CVE-2026-64623 | HIGH | 8.6 | Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers … | Jul 20, 2026 |
| CVE-2026-64622 | HIGH | 7.5 | Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an … | Jul 20, 2026 |
| CVE-2026-64621 | HIGH | 7.3 | FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The … | Jul 20, 2026 |
| CVE-2026-64620 | CRITICAL | 9.8 | FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via … | Jul 20, 2026 |
| CVE-2026-63763 | UNKNOWN | — | SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or … | Jul 20, 2026 |
| CVE-2026-63762 | UNKNOWN | — | SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability … | Jul 20, 2026 |
| CVE-2026-63761 | MEDIUM | 4.3 | SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), … | Jul 20, 2026 |
| CVE-2026-63760 | HIGH | 7.5 | SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated … | Jul 20, 2026 |
| CVE-2026-63759 | MEDIUM | 6.5 | SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply … | Jul 20, 2026 |
| CVE-2026-63758 | MEDIUM | 5.4 | SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. … | Jul 20, 2026 |
| CVE-2026-63757 | HIGH | 8.8 | SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session … | Jul 20, 2026 |