Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52066
Total
4132
Critical
15433
High
15137
Medium
CVE ID Severity Score Description Published
CVE-2026-12391 MEDIUM 5.0 An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file … Jul 16, 2026
CVE-2026-11386 CRITICAL 9.0 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) … Jul 16, 2026
CVE-2025-71388 UNKNOWN — stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, … Jul 16, 2026
CVE-2025-71377 UNKNOWN — stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can … Jul 16, 2026
CVE-2024-58360 MEDIUM 6.5 stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with … Jul 16, 2026
CVE-2026-59249 UNKNOWN — Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint … Jul 16, 2026
CVE-2026-35149 HIGH 8.2 HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting … Jul 16, 2026
CVE-2026-35148 MEDIUM 6.3 HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another … Jul 16, 2026
CVE-2026-35147 HIGH 8.2 HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific … Jul 16, 2026
CVE-2026-35146 MEDIUM 6.3 HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could … Jul 16, 2026
CVE-2023-49900 CRITICAL 9.8 An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. Jul 16, 2026
CVE-2023-49899 CRITICAL 9.8 An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel. Jul 16, 2026
CVE-2026-22752 CRITICAL 9.6 Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through … Jul 16, 2026
CVE-2026-7543 HIGH 7.2 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient … Jul 16, 2026
CVE-2026-6424 UNKNOWN — Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system Jul 16, 2026
CVE-2026-6423 UNKNOWN — A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authentication in an IPC channel. Jul 16, 2026
CVE-2026-58078 UNKNOWN — The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection. Jul 16, 2026
CVE-2026-15727 MEDIUM 4.9 The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 … Jul 16, 2026
CVE-2026-15651 MEDIUM 4.9 The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, … Jul 16, 2026
CVE-2026-15610 MEDIUM 4.3 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Jul 16, 2026
CVE-2026-15407 MEDIUM 4.3 The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin … Jul 16, 2026
CVE-2026-15350 MEDIUM 4.3 The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the … Jul 16, 2026
CVE-2026-15324 MEDIUM 4.4 The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter … Jul 16, 2026
CVE-2026-15106 MEDIUM 5.3 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, … Jul 16, 2026
CVE-2026-15103 HIGH 8.8 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update … Jul 16, 2026