Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51856
Total
4111
Critical
15381
High
15070
Medium
CVE ID Severity Score Description Published
CVE-2026-16210 HIGH 7.3 A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a … Jul 19, 2026
CVE-2026-16209 HIGH 7.3 A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project … Jul 19, 2026
CVE-2026-16208 MEDIUM 5.0 A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. This manipulation causes race … Jul 19, 2026
CVE-2026-16207 LOW 3.7 A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get … Jul 19, 2026
CVE-2026-16206 MEDIUM 6.3 A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session … Jul 19, 2026
CVE-2026-16205 LOW 2.4 A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums … Jul 19, 2026
CVE-2026-16204 MEDIUM 6.3 A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI … Jul 19, 2026
CVE-2026-16203 LOW 3.5 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such … Jul 19, 2026
CVE-2026-16202 LOW 3.5 A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This … Jul 19, 2026
CVE-2026-16201 MEDIUM 5.3 A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation … Jul 19, 2026
CVE-2026-16200 HIGH 7.3 A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. … Jul 19, 2026
CVE-2026-16199 MEDIUM 6.3 A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead … Jul 19, 2026
CVE-2026-16198 MEDIUM 5.6 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First … Jul 19, 2026
CVE-2026-16197 MEDIUM 6.3 A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the … Jul 18, 2026
CVE-2026-16196 MEDIUM 6.3 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This … Jul 18, 2026
CVE-2026-16195 MEDIUM 6.3 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component … Jul 18, 2026
CVE-2026-10130 HIGH 8.2 QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a … Jul 18, 2026
CVE-2026-16194 MEDIUM 6.3 A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument … Jul 18, 2026
CVE-2026-16156 LOW 3.5 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation … Jul 18, 2026
CVE-2026-57857 MEDIUM 4.3 The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an … Jul 18, 2026
CVE-2026-16155 LOW 3.5 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The … Jul 18, 2026
CVE-2026-16154 HIGH 7.3 A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing … Jul 18, 2026
CVE-2026-16152 HIGH 7.3 A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of … Jul 18, 2026
CVE-2026-12228 HIGH 8.7 A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side … Jul 18, 2026
CVE-2026-57848 MEDIUM 5.5 Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as … Jul 18, 2026