Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

53238
Total
4231
Critical
15843
High
15500
Medium
CVE ID Severity Score Description Published
CVE-2026-15191 MEDIUM 6.3 A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettle/sendportal-core/src/Http/Requests/CampaignStoreRequest.php of the component Campaign Creation … Jul 09, 2026
CVE-2026-15190 HIGH 7.3 A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation … Jul 09, 2026
CVE-2026-13462 HIGH 7.5 PayRange Android app, version 7.0.7 and below, contains an SSL bypass vulnerability that allows invalid certificates to be accepted in application webviews. A remote and … Jul 09, 2026
CVE-2026-13461 UNKNOWN — When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript … Jul 09, 2026
CVE-2026-61474 UNKNOWN — An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to add attributes to submit a sharing_group_id without triggering the … Jul 09, 2026
CVE-2026-59208 MEDIUM 6.8 n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted … Jul 09, 2026
CVE-2026-59207 MEDIUM 6.5 n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce the Allowed HTTP Request Domains … Jul 09, 2026
CVE-2026-59206 HIGH 7.1 n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype … Jul 09, 2026
CVE-2026-58125 UNKNOWN — Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jul 09, 2026
CVE-2026-42486 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … Jul 09, 2026
CVE-2026-23562 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … Jul 09, 2026
CVE-2026-23561 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … Jul 09, 2026
CVE-2026-23560 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … Jul 09, 2026
CVE-2026-23559 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, … Jul 09, 2026
CVE-2026-23556 UNKNOWN — When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually … Jul 09, 2026
CVE-2026-15189 MEDIUM 6.3 A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is the function upload_media of the component mcp-whatsapp. Such … Jul 09, 2026
CVE-2026-15188 MEDIUM 6.3 A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is the function EditEmployeeProfileAPIView of the file accounts/api/views.py of the … Jul 09, 2026
CVE-2026-15187 MEDIUM 4.3 A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of … Jul 09, 2026
CVE-2026-11404 HIGH 7.5 Cesanta Mongoose before 7.22 contains an out-of-bounds read in the built-in TLS server function mg_tls_server_recv_hello(), which uses an attacker-controlled session_id_len byte from a TLS ClientHello … Jul 09, 2026
CVE-2025-58151 UNKNOWN — varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving … Jul 09, 2026
CVE-2025-58146 UNKNOWN — There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised input. This causes the … Jul 09, 2026
CVE-2025-27464 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to … Jul 09, 2026
CVE-2025-27463 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to … Jul 09, 2026
CVE-2025-27462 UNKNOWN — [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to … Jul 09, 2026
CVE-2026-60109 HIGH 7.5 Zeek before 8.0.9 contains a null pointer dereference vulnerability in its Kerberos protocol analyzer that allows unauthenticated remote attackers to crash the sensor by sending … Jul 09, 2026