Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52066
Total
4132
Critical
15433
High
15137
Medium
CVE ID Severity Score Description Published
CVE-2026-44177 UNKNOWN — Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, … Jul 16, 2026
CVE-2026-44176 UNKNOWN — Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are … Jul 16, 2026
CVE-2026-44175 UNKNOWN — Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field … Jul 16, 2026
CVE-2026-44174 UNKNOWN — Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection … Jul 16, 2026
CVE-2026-14782 MEDIUM 4.9 The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up … Jul 16, 2026
CVE-2026-13713 MEDIUM 6.2 YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the … Jul 16, 2026
CVE-2026-61378 MEDIUM 5.5 A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash. Jul 16, 2026
CVE-2026-60073 MEDIUM 5.9 An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead … Jul 16, 2026
CVE-2026-57896 MEDIUM 6.1 An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could … Jul 16, 2026
CVE-2026-55173 HIGH 8.1 WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete … Jul 16, 2026
CVE-2026-53410 HIGH 7.0 A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user … Jul 16, 2026
CVE-2026-53409 HIGH 7.8 Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. Jul 16, 2026
CVE-2026-44023 HIGH 8.6 Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not … Jul 16, 2026
CVE-2026-44019 HIGH 8.1 Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow … Jul 16, 2026
CVE-2026-38158 CRITICAL 9.8 A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. Jul 16, 2026
CVE-2026-36425 MEDIUM 6.5 An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination … Jul 16, 2026
CVE-2026-33731 MEDIUM 6.5 WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that … Jul 16, 2026
CVE-2026-33692 HIGH 7.5 WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The … Jul 16, 2026
CVE-2026-11889 MEDIUM 6.5 SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to … Jul 16, 2026
CVE-2024-34268 HIGH 7.1 EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers … Jul 16, 2026
CVE-2024-32389 LOW 3.5 Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component. Jul 16, 2026
CVE-2024-32387 MEDIUM 5.7 An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component. Jul 16, 2026
CVE-2024-32386 HIGH 7.3 Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism. Jul 16, 2026
CVE-2024-32385 MEDIUM 4.3 An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components Jul 16, 2026
CVE-2026-63397 MEDIUM 6.4 remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. … Jul 16, 2026