Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52341
Total
4150
Critical
15505
High
15208
Medium
CVE ID Severity Score Description Published
CVE-2026-52839 LOW 3.3 Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 correctly filter provider-scoped appointments in the `appointments/search` response, proving that provider isolation is an … Jul 14, 2026
CVE-2026-52838 LOW 2.6 Easy!Appointments is a self hosted appointment scheduler. Versions prior to 1.6.0 allow administrators to define a custom "booking disabled" message through the booking settings page. … Jul 14, 2026
CVE-2026-23573 MEDIUM 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS … Jul 14, 2026
CVE-2026-15699 MEDIUM 6.3 A vulnerability was identified in spencermountain compromise up to 14.15.1. Affected is the function nlp.extend of the file src/API/extend.js of the component Public Root API. … Jul 14, 2026
CVE-2026-15698 MEDIUM 6.3 A vulnerability was determined in kofrasa mingo up to 7.2.1. This impacts the function update/updateOne/updateMany of the component Update API. Executing a manipulation of the … Jul 14, 2026
CVE-2026-15697 MEDIUM 6.3 A vulnerability was found in svgdotjs svg.js up to 3.2.5. This affects the function EventTarget.on of the file svgdotjs/svg.js of the component npm Package API. … Jul 14, 2026
CVE-2026-15392 UNKNOWN — DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the … Jul 14, 2026
CVE-2026-14504 UNKNOWN — An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository … Jul 14, 2026
CVE-2026-12707 HIGH 7.5 Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the … Jul 14, 2026
CVE-2026-12659 UNKNOWN — A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent … Jul 14, 2026
CVE-2026-12523 HIGH 7.5 Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines … Jul 14, 2026
CVE-2026-11944 MEDIUM 6.5 openSIS Classic 9.3 contains an authenticated path traversal vulnerability in the legacy messaging sent-mail attachment download functionality that allows an authenticated attacker to read arbitrary … Jul 14, 2026
CVE-2026-11917 UNKNOWN — A path traversal security issue exists within Rockwell Automation ThinManager® software due to improper limitation of file save operations within the API. An authenticated attacker … Jul 14, 2026
CVE-2026-11403 UNKNOWN — A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a … Jul 14, 2026
CVE-2025-62826 LOW 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, … Jul 14, 2026
CVE-2025-62675 LOW 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, … Jul 14, 2026
CVE-2025-53379 HIGH 7.5 A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via … Jul 14, 2026
CVE-2025-43892 MEDIUM 4.3 A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to … Jul 14, 2026
CVE-2025-11698 UNKNOWN — A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file … Jul 14, 2026
CVE-2026-9653 UNKNOWN — A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker … Jul 14, 2026
CVE-2026-9140 UNKNOWN — A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device … Jul 14, 2026
CVE-2026-8590 UNKNOWN — Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This … Jul 14, 2026
CVE-2026-60114 HIGH 7.5 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to … Jul 14, 2026
CVE-2026-58479 CRITICAL 9.8 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers … Jul 14, 2026
CVE-2026-58478 MEDIUM 6.5 Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make the device issue arbitrary HTTP … Jul 14, 2026