Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52066
Total
4132
Critical
15433
High
15137
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12391 | MEDIUM | 5.0 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file … | Jul 16, 2026 |
| CVE-2026-11386 | CRITICAL | 9.0 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) … | Jul 16, 2026 |
| CVE-2025-71388 | UNKNOWN | — | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, … | Jul 16, 2026 |
| CVE-2025-71377 | UNKNOWN | — | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can … | Jul 16, 2026 |
| CVE-2024-58360 | MEDIUM | 6.5 | stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with … | Jul 16, 2026 |
| CVE-2026-59249 | UNKNOWN | — | Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint … | Jul 16, 2026 |
| CVE-2026-35149 | HIGH | 8.2 | HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting … | Jul 16, 2026 |
| CVE-2026-35148 | MEDIUM | 6.3 | HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another … | Jul 16, 2026 |
| CVE-2026-35147 | HIGH | 8.2 | HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific … | Jul 16, 2026 |
| CVE-2026-35146 | MEDIUM | 6.3 | HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could … | Jul 16, 2026 |
| CVE-2023-49900 | CRITICAL | 9.8 | An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. | Jul 16, 2026 |
| CVE-2023-49899 | CRITICAL | 9.8 | An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel. | Jul 16, 2026 |
| CVE-2026-22752 | CRITICAL | 9.6 | Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through … | Jul 16, 2026 |
| CVE-2026-7543 | HIGH | 7.2 | The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient … | Jul 16, 2026 |
| CVE-2026-6424 | UNKNOWN | — | Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system | Jul 16, 2026 |
| CVE-2026-6423 | UNKNOWN | — | A local privilege escalation vulnerability in ESET Inspect Connector. The vulnerability was caused by improper authentication in an IPC channel. | Jul 16, 2026 |
| CVE-2026-58078 | UNKNOWN | — | The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection. | Jul 16, 2026 |
| CVE-2026-15727 | MEDIUM | 4.9 | The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 … | Jul 16, 2026 |
| CVE-2026-15651 | MEDIUM | 4.9 | The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, … | Jul 16, 2026 |
| CVE-2026-15610 | MEDIUM | 4.3 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, … | Jul 16, 2026 |
| CVE-2026-15407 | MEDIUM | 4.3 | The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin … | Jul 16, 2026 |
| CVE-2026-15350 | MEDIUM | 4.3 | The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the … | Jul 16, 2026 |
| CVE-2026-15324 | MEDIUM | 4.4 | The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter … | Jul 16, 2026 |
| CVE-2026-15106 | MEDIUM | 5.3 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, … | Jul 16, 2026 |
| CVE-2026-15103 | HIGH | 8.8 | The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update … | Jul 16, 2026 |