Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
52613
Total
4187
Critical
15589
High
15276
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12385 | MEDIUM | 4.3 | The Smart Slider 3 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1.37 via the 'keyword' parameter. … | Jul 13, 2026 |
| CVE-2026-6875 | UNKNOWN | — | ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain … | Jul 13, 2026 |
| CVE-2026-58228 | UNKNOWN | — | Cross-site scripting vulnerability in phoenixframework phoenix_live_view allows an attacker to bypass URL scheme validation and execute JavaScript in a victim's browser session. The Phoenix.LiveView.Utils.valid_destination!/2 and … | Jul 13, 2026 |
| CVE-2026-55772 | HIGH | 8.8 | CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3.6, 3.4.1 and 4.9.0, … | Jul 13, 2026 |
| CVE-2026-49972 | HIGH | 8.8 | Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP … | Jul 13, 2026 |
| CVE-2026-49971 | MEDIUM | 6.1 | Laravel-Mediable before 7.0.0 contains a stored cross-site scripting vulnerability that allows authenticated or anonymous users to execute arbitrary JavaScript by uploading unsanitized SVG files containing … | Jul 13, 2026 |
| CVE-2026-49970 | HIGH | 8.8 | Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the … | Jul 13, 2026 |
| CVE-2026-49969 | HIGH | 7.4 | Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled … | Jul 13, 2026 |
| CVE-2026-26396 | HIGH | 7.5 | OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The input parameter “filename” is user-controllable and is concatenated … | Jul 13, 2026 |
| CVE-2026-14906 | MEDIUM | 5.3 | Pages with malicious titles could potentially allow saved PDF content to overwrite PDF files or bundled content within the Firefox for iOS application sandbox. This … | Jul 13, 2026 |
| CVE-2025-45869 | HIGH | 7.3 | LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit the ShareFileCallback servlet by manipulating … | Jul 13, 2026 |
| CVE-2026-61505 | MEDIUM | 5.3 | Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain JSON files outside the … | Jul 13, 2026 |
| CVE-2026-61504 | MEDIUM | 5.4 | Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser … | Jul 13, 2026 |
| CVE-2026-61503 | MEDIUM | 5.3 | Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A remote unauthenticated attacker can … | Jul 13, 2026 |
| CVE-2026-61502 | MEDIUM | 4.3 | Rejetto HFS 3.0.0 through 3.2.0 accepts state-changing API requests via the GET method and exempts GET requests from its anti-CSRF header check. A remote attacker … | Jul 13, 2026 |
| CVE-2026-61501 | MEDIUM | 6.1 | Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can submit a failed login … | Jul 13, 2026 |
| CVE-2026-61500 | CRITICAL | 9.8 | Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients … | Jul 13, 2026 |
| CVE-2026-61463 | HIGH | 8.8 | Shiori contains a privilege escalation vulnerability in the account update endpoint that allows authenticated users to modify the owner field without authorization checks. Attackers can … | Jul 13, 2026 |
| CVE-2026-61462 | HIGH | 8.6 | mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can … | Jul 13, 2026 |
| CVE-2026-60103 | MEDIUM | 6.1 | Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted … | Jul 13, 2026 |
| CVE-2026-53365 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix zerocopy completion for multi-skb sends When a large message is fragmented into multiple … | Jul 13, 2026 |
| CVE-2026-53364 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_conn: Fix memory leak in hci_le_big_terminate() hci_le_big_terminate() allocates iso_list_data via kzalloc_obj but returns 0 … | Jul 13, 2026 |
| CVE-2026-57433 | CRITICAL | 9.8 | Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from … | Jul 13, 2026 |
| CVE-2026-57432 | HIGH | 8.4 | Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size … | Jul 13, 2026 |
| CVE-2026-13221 | CRITICAL | 9.1 | Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie … | Jul 13, 2026 |