Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-44177 | UNKNOWN | — | Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user ID, … | Jul 16, 2026 |
| CVE-2026-44176 | UNKNOWN | — | Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft rendering. Permissions are … | Jul 16, 2026 |
| CVE-2026-44175 | UNKNOWN | — | Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list field … | Jul 16, 2026 |
| CVE-2026-44174 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collection … | Jul 16, 2026 |
| CVE-2026-14782 | MEDIUM | 4.9 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the Customer Import in all versions up … | Jul 16, 2026 |
| CVE-2026-13713 | MEDIUM | 6.2 | YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack. In the … | Jul 16, 2026 |
| CVE-2026-61378 | MEDIUM | 5.5 | A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash. | Jul 16, 2026 |
| CVE-2026-60073 | MEDIUM | 5.9 | An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead … | Jul 16, 2026 |
| CVE-2026-57896 | MEDIUM | 6.1 | An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCTL request. This could … | Jul 16, 2026 |
| CVE-2026-55173 | HIGH | 8.1 | WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete … | Jul 16, 2026 |
| CVE-2026-53410 | HIGH | 7.0 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user … | Jul 16, 2026 |
| CVE-2026-53409 | HIGH | 7.8 | Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access. | Jul 16, 2026 |
| CVE-2026-44023 | HIGH | 8.6 | Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.1, docling-core did not … | Jul 16, 2026 |
| CVE-2026-44019 | HIGH | 8.1 | Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.1, docling-core could allow … | Jul 16, 2026 |
| CVE-2026-38158 | CRITICAL | 9.8 | A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements. | Jul 16, 2026 |
| CVE-2026-36425 | MEDIUM | 6.5 | An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination … | Jul 16, 2026 |
| CVE-2026-33731 | MEDIUM | 6.5 | WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that … | Jul 16, 2026 |
| CVE-2026-33692 | HIGH | 7.5 | WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The … | Jul 16, 2026 |
| CVE-2026-11889 | MEDIUM | 6.5 | SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an authorized attacker to … | Jul 16, 2026 |
| CVE-2024-34268 | HIGH | 7.1 | EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers … | Jul 16, 2026 |
| CVE-2024-32389 | LOW | 3.5 | Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component. | Jul 16, 2026 |
| CVE-2024-32387 | MEDIUM | 5.7 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component. | Jul 16, 2026 |
| CVE-2024-32386 | HIGH | 7.3 | Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism. | Jul 16, 2026 |
| CVE-2024-32385 | MEDIUM | 4.3 | An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components | Jul 16, 2026 |
| CVE-2026-63397 | MEDIUM | 6.4 | remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary JavaScript or TypeScript. … | Jul 16, 2026 |