Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-15191 | MEDIUM | 6.3 | A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation … | Jul 09, 2026 |
| CVE-2026-15190 | HIGH | 7.3 | A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation … | Jul 09, 2026 |
| CVE-2026-13462 | HIGH | 7.5 | PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and … | Jul 09, 2026 |
| CVE-2026-13461 | UNKNOWN | — | When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript … | Jul 09, 2026 |
| CVE-2026-61474 | UNKNOWN | — | An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the … | Jul 09, 2026 |
| CVE-2026-59208 | MEDIUM | 6.8 | n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted … | Jul 09, 2026 |
| CVE-2026-59207 | MEDIUM | 6.5 | n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains … | Jul 09, 2026 |
| CVE-2026-59206 | HIGH | 7.1 | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype … | Jul 09, 2026 |
| CVE-2026-58125 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Jul 09, 2026 |
| CVE-2026-42486 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … | Jul 09, 2026 |
| CVE-2026-23562 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … | Jul 09, 2026 |
| CVE-2026-23561 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … | Jul 09, 2026 |
| CVE-2026-23560 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … | Jul 09, 2026 |
| CVE-2026-23559 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … | Jul 09, 2026 |
| CVE-2026-23556 | UNKNOWN | — | When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually … | Jul 09, 2026 |
| CVE-2026-15189 | MEDIUM | 6.3 | A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such … | Jul 09, 2026 |
| CVE-2026-15188 | MEDIUM | 6.3 | A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the … | Jul 09, 2026 |
| CVE-2026-15187 | MEDIUM | 4.3 | A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of … | Jul 09, 2026 |
| CVE-2026-11404 | HIGH | 7.5 | Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello … | Jul 09, 2026 |
| CVE-2025-58151 | UNKNOWN | — | varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving … | Jul 09, 2026 |
| CVE-2025-58146 | UNKNOWN | — | There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised input. This causes the … | Jul 09, 2026 |
| CVE-2025-27464 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to … | Jul 09, 2026 |
| CVE-2025-27463 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to … | Jul 09, 2026 |
| CVE-2025-27462 | UNKNOWN | — | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to … | Jul 09, 2026 |
| CVE-2026-60109 | HIGH | 7.5 | Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending … | Jul 09, 2026 |