Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-0276 | UNKNOWN | — | A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user. | Jul 09, 2026 |
| CVE-2026-0275 | UNKNOWN | — | A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform … | Jul 09, 2026 |
| CVE-2026-59149 | MEDIUM | 6.5 | Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is confined by getSafeFilePath in … | Jul 09, 2026 |
| CVE-2026-59148 | HIGH | 8.8 | Mockoon provides way to design and run mock APIs. Prior to 9.7.0, Mockoon's admin API in commons-server/src/libs/server/admin-api.ts is mounted on the same Express listener as … | Jul 09, 2026 |
| CVE-2026-58198 | MEDIUM | 5.5 | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a … | Jul 09, 2026 |
| CVE-2026-55590 | UNKNOWN | — | CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Prior to 2.11.1, 3.3.6, and 4.1.1, the getLoginRedirect() … | Jul 09, 2026 |
| CVE-2026-54695 | HIGH | 7.5 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0, the pipecat development runner registers a /ws WebSocket … | Jul 09, 2026 |
| CVE-2026-54005 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites where a role has the pages.access permission disabled allowed authenticated users … | Jul 09, 2026 |
| CVE-2026-54004 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites with content.fileRedirects enabled could redirect unauthenticated clean file URL requests for … | Jul 09, 2026 |
| CVE-2026-54003 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible … | Jul 09, 2026 |
| CVE-2026-54002 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins that use the writer or list fields or call … | Jul 09, 2026 |
| CVE-2026-50188 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites and plugins using the Kirby Http Remote class, including Remote::request(), Remote::get(), … | Jul 09, 2026 |
| CVE-2026-49276 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the writer field in any blueprint allowed a scripting link … | Jul 09, 2026 |
| CVE-2026-49274 | UNKNOWN | — | Kirby is an open-source content management system. Prior to 4.9.4 and 5.4.4, Kirby sites using the pages field with roles that have the pages.access permission … | Jul 09, 2026 |
| CVE-2026-13492 | HIGH | 8.8 | The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.65. This is due to insufficient validation of … | Jul 09, 2026 |
| CVE-2026-0287 | UNKNOWN | — | Multiple denial of service vulnerabilities in Palo Alto Networks PAN-OS® software allow an unauthenticated attacker with network access to cause a denial of service (DoS) … | Jul 09, 2026 |
| CVE-2026-0286 | UNKNOWN | — | A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. … | Jul 09, 2026 |
| CVE-2026-0285 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator with network access to the management web interface to … | Jul 09, 2026 |
| CVE-2026-0284 | UNKNOWN | — | An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to … | Jul 09, 2026 |
| CVE-2026-0283 | UNKNOWN | — | An authentication bypass vulnerability in Large Scale VPN ( LSVPN) functionality of Palo Alto Networks PAN-OS software allows an attacker with network access to bypass … | Jul 09, 2026 |
| CVE-2026-0282 | UNKNOWN | — | A file deletion vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to delete files … | Jul 09, 2026 |
| CVE-2026-0281 | UNKNOWN | — | An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web interface to obtain web … | Jul 09, 2026 |
| CVE-2026-0280 | UNKNOWN | — | An IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker to bypass firewall security policy enforcement, allowing … | Jul 09, 2026 |
| CVE-2026-0279 | UNKNOWN | — | Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® … | Jul 09, 2026 |
| CVE-2025-63579 | HIGH | 7.5 | Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian … | Jul 09, 2026 |