Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52341
Total
4150
Critical
15505
High
15208
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52839 | LOW | 3.3 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an … | Jul 14, 2026 |
| CVE-2026-52838 | LOW | 2.6 | Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. … | Jul 14, 2026 |
| CVE-2026-23573 | MEDIUM | 6.1 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS … | Jul 14, 2026 |
| CVE-2026-15699 | MEDIUM | 6.3 | A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. … | Jul 14, 2026 |
| CVE-2026-15698 | MEDIUM | 6.3 | A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the … | Jul 14, 2026 |
| CVE-2026-15697 | MEDIUM | 6.3 | A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. … | Jul 14, 2026 |
| CVE-2026-15392 | UNKNOWN | — | DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the … | Jul 14, 2026 |
| CVE-2026-14504 | UNKNOWN | — | An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository … | Jul 14, 2026 |
| CVE-2026-12707 | HIGH | 7.5 | Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the … | Jul 14, 2026 |
| CVE-2026-12659 | UNKNOWN | — | A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent … | Jul 14, 2026 |
| CVE-2026-12523 | HIGH | 7.5 | Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines … | Jul 14, 2026 |
| CVE-2026-11944 | MEDIUM | 6.5 | openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary … | Jul 14, 2026 |
| CVE-2026-11917 | UNKNOWN | — | A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker … | Jul 14, 2026 |
| CVE-2026-11403 | UNKNOWN | — | A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a … | Jul 14, 2026 |
| CVE-2025-62826 | LOW | 3.1 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, … | Jul 14, 2026 |
| CVE-2025-62675 | LOW | 3.4 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, … | Jul 14, 2026 |
| CVE-2025-53379 | HIGH | 7.5 | A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via … | Jul 14, 2026 |
| CVE-2025-43892 | MEDIUM | 4.3 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to … | Jul 14, 2026 |
| CVE-2025-11698 | UNKNOWN | — | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file … | Jul 14, 2026 |
| CVE-2026-9653 | UNKNOWN | — | A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker … | Jul 14, 2026 |
| CVE-2026-9140 | UNKNOWN | — | A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device … | Jul 14, 2026 |
| CVE-2026-8590 | UNKNOWN | — | Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This … | Jul 14, 2026 |
| CVE-2026-60114 | HIGH | 7.5 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to … | Jul 14, 2026 |
| CVE-2026-58479 | CRITICAL | 9.8 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers … | Jul 14, 2026 |
| CVE-2026-58478 | MEDIUM | 6.5 | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP … | Jul 14, 2026 |