Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51763
Total
4101
Critical
15352
High
15010
Medium
CVE ID Severity Score Description Published
CVE-2026-51386 UNKNOWN — Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2026-46409. Reason: This record is a reservation duplicate of CVE-2026-46409. Notes: All CVE users should reference … Jul 20, 2026
CVE-2026-46516 UNKNOWN — Frogman provides headless FreePBX control. Prior to version 1.6.6, Frogman's chat-console markdown formatter (`assets/js/chat.js`'s `formatMarkdown`) inserted regex capture groups as raw HTML in four template … Jul 20, 2026
CVE-2026-46410 UNKNOWN — FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. … Jul 20, 2026
CVE-2026-45270 HIGH 8.7 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` validation rule on language-keyed page … Jul 20, 2026
CVE-2026-45139 MEDIUM 6.5 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (`['css','js','html','txt','json','sql','md']`) on content-write operations (`saveFile`, … Jul 20, 2026
CVE-2026-16277 MEDIUM 6.5 A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information returned by the server … Jul 20, 2026
CVE-2026-16252 HIGH 7.3 A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown function of the file … Jul 20, 2026
CVE-2026-12701 CRITICAL 9.0 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block … Jul 20, 2026
CVE-2026-57311 UNKNOWN — Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution. … Jul 20, 2026
CVE-2026-57310 UNKNOWN — Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash … Jul 20, 2026
CVE-2026-57309 UNKNOWN — A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in … Jul 20, 2026
CVE-2026-16248 HIGH 8.8 A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of … Jul 20, 2026
CVE-2026-16244 MEDIUM 6.3 A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /prescriptionorderreport.php. Such … Jul 20, 2026
CVE-2026-12080 HIGH 7.3 A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command handler by manipulating … Jul 20, 2026
CVE-2026-64623 HIGH 8.6 Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accepts any non-empty string as valid. Unauthenticated attackers … Jul 20, 2026
CVE-2026-64622 HIGH 7.5 Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox GET read routes, so even when an … Jul 20, 2026
CVE-2026-64621 HIGH 7.3 FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The … Jul 20, 2026
CVE-2026-64620 CRITICAL 9.8 FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based buffer overflow in crypto_rsa_common() (libfreerdp/crypto/crypto.c). The function writes the modular-exponentiation result into the caller's output buffer via … Jul 20, 2026
CVE-2026-63763 UNKNOWN — SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or … Jul 20, 2026
CVE-2026-63762 UNKNOWN — SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability in its embedded JavaScript scripting engine, which is enabled via the --allow-scripting capability … Jul 20, 2026
CVE-2026-63761 MEDIUM 4.3 SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES512 (DEFINE ACCESS ... TYPE JWT ALGORITHM ES512), … Jul 20, 2026
CVE-2026-63760 HIGH 7.5 SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or parentheses. Unauthenticated … Jul 20, 2026
CVE-2026-63759 MEDIUM 6.5 SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when processing nested type annotations. Authenticated attackers can send queries with deeply … Jul 20, 2026
CVE-2026-63758 MEDIUM 5.4 SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. … Jul 20, 2026
CVE-2026-63757 HIGH 8.8 SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session … Jul 20, 2026