Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
34313
Total
2675
Critical
10128
High
10348
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-0688 | MEDIUM | 6.4 | The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 via the 'Tools::read' function. This makes … | Apr 02, 2026 |
| CVE-2026-0686 | HIGH | 7.2 | The Webmention plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.6.2 in the 'MF2::parse_authorpage' function via the … | Apr 02, 2026 |
| CVE-2026-5325 | LOW | 3.5 | A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component … | Apr 02, 2026 |
| CVE-2026-5323 | MEDIUM | 5.3 | A vulnerability was found in priyankark a11y-mcp up to 1.0.5. This vulnerability affects the function A11yServer of the file src/index.js. The manipulation results in server-side … | Apr 02, 2026 |
| CVE-2026-5322 | HIGH | 7.3 | A vulnerability has been found in AlejandroArciniegas mcp-data-vis bc597e391f184d2187062fd567599a3cb72adf51/de5a51525a69822290eaee569a1ab447b490746d. This affects the function Request of the file src/servers/database/server.js of the component MCP Handler. The manipulation … | Apr 02, 2026 |
| CVE-2026-4347 | HIGH | 8.1 | The MW WP Form plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the 'generate_user_filepath' function and the … | Apr 02, 2026 |
| CVE-2026-1540 | HIGH | 7.2 | The Spam Protect for Contact Form 7 WordPress plugin before 1.2.10 allows logging to a PHP file, which could allow an attacker with editor access … | Apr 02, 2026 |
| CVE-2026-5321 | MEDIUM | 4.3 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing … | Apr 02, 2026 |
| CVE-2026-5320 | HIGH | 7.3 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component … | Apr 02, 2026 |
| CVE-2026-5319 | MEDIUM | 4.3 | A security vulnerability has been detected in itsourcecode Payroll Management System up to 1.0. Affected is an unknown function of the file /navbar.php. Such manipulation … | Apr 02, 2026 |
| CVE-2026-5318 | MEDIUM | 4.3 | A weakness has been identified in LibRaw up to 0.22.0. This impacts the function HuffTable::initval of the file src/decompressors/losslessjpeg.cpp of the component JPEG DHT Parser. … | Apr 02, 2026 |
| CVE-2026-5317 | MEDIUM | 6.3 | A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in … | Apr 02, 2026 |
| CVE-2026-1243 | MEDIUM | 5.4 | IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the … | Apr 02, 2026 |
| CVE-2026-5316 | MEDIUM | 4.3 | A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to … | Apr 02, 2026 |
| CVE-2026-5315 | MEDIUM | 4.3 | A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF … | Apr 02, 2026 |
| CVE-2026-21767 | MEDIUM | 4.0 | HCL BigFix Platform is affected by insufficient authentication. The application might allow users to access sensitive areas of the application without proper authentication. | Apr 02, 2026 |
| CVE-2026-21765 | HIGH | 8.8 | HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject … | Apr 02, 2026 |
| CVE-2026-5314 | MEDIUM | 4.3 | A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. … | Apr 01, 2026 |
| CVE-2026-4759 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Apr 01, 2026 |
| CVE-2026-3882 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Apr 01, 2026 |
| CVE-2026-32929 | HIGH | 7.8 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product. | Apr 01, 2026 |
| CVE-2026-32928 | HIGH | 7.8 | V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the … | Apr 01, 2026 |
| CVE-2026-32927 | HIGH | 7.8 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected … | Apr 01, 2026 |
| CVE-2026-32926 | HIGH | 7.8 | V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected … | Apr 01, 2026 |
| CVE-2026-32925 | HIGH | 7.8 | V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CV7BaseMap::WriteV7DataToRom. Opening a crafted V7 file may lead to arbitrary code execution on the … | Apr 01, 2026 |