Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

52671
Total
4197
Critical
15603
High
15291
Medium
CVE ID Severity Score Description Published
CVE-2026-15545 HIGH 8.8 A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatodata.cgi of the component … Jul 13, 2026
CVE-2026-14453 CRITICAL 9.6 This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without … Jul 13, 2026
CVE-2026-10106 MEDIUM 6.5 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify that the channel referenced in an action cookie matches the channel … Jul 13, 2026
CVE-2026-10103 MEDIUM 4.3 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to verify post ownership in the shared channel inbound sync handler, which allows … Jul 13, 2026
CVE-2026-10085 MEDIUM 5.4 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to restrict the group_constrained channel flag to public and private channels that support … Jul 13, 2026
CVE-2026-57830 UNKNOWN — The Joomla extension Helix Ultimate is vulnerable to an unauthenticated arbitrary file deletion. Jul 13, 2026
CVE-2026-57829 UNKNOWN — The Joomla extension Helix Ultimate is vulnerable to an unauthenticated stored XSS. Jul 13, 2026
CVE-2026-4769 CRITICAL 9.8 Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented … Jul 13, 2026
CVE-2026-15544 HIGH 8.8 A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the component apcupsd. This manipulation … Jul 13, 2026
CVE-2026-15543 HIGH 8.8 A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the argument Name results in … Jul 13, 2026
CVE-2026-15542 HIGH 7.3 A vulnerability has been found in will-moss Isaiah up to 1.36.9. This affects an unknown function of the file app/main.go of the component Websocket Connection … Jul 13, 2026
CVE-2026-15541 HIGH 7.3 A flaw has been found in will-moss Isaiah up to 1.36.9. The impacted element is the function Server.Handle of the file app/server/server/server.go of the component … Jul 13, 2026
CVE-2026-15540 MEDIUM 4.3 A vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component … Jul 13, 2026
CVE-2026-14165 HIGH 7.5 An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to access data of other users … Jul 13, 2026
CVE-2026-15539 MEDIUM 4.7 A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component … Jul 13, 2026
CVE-2026-15538 MEDIUM 6.3 A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component API. This manipulation of the … Jul 13, 2026
CVE-2026-15537 HIGH 7.3 A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of … Jul 13, 2026
CVE-2026-15536 MEDIUM 6.3 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid … Jul 13, 2026
CVE-2026-12582 HIGH 8.6 The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing unauthenticated … Jul 13, 2026
CVE-2026-12397 MEDIUM 4.3 The WP Job Portal WordPress plugin before 2.5.5 does not verify ownership when returning an employer's contact email for a given job, allowing authenticated users … Jul 13, 2026
CVE-2026-12396 MEDIUM 5.4 The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing authenticated users with a … Jul 13, 2026
CVE-2026-12275 HIGH 7.1 The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and private-course capability checks it … Jul 13, 2026
CVE-2026-12274 MEDIUM 6.5 The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in … Jul 13, 2026
CVE-2026-12273 MEDIUM 4.3 The Tutor LMS WordPress plugin before 3.9.13 does not perform any authorization or post-target validation before creating a comment in one of its handlers, and … Jul 13, 2026
CVE-2026-12271 MEDIUM 5.4 The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated users with subscriber-level … Jul 13, 2026