Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42683
Total
3463
Critical
12701
High
12563
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-5096 | MEDIUM | 5.3 | The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the … | Aug 28, 2026 |
| CVE-2026-58107 | UNKNOWN | — | CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store … | Aug 28, 2026 |
| CVE-2026-58106 | UNKNOWN | — | CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, … | Aug 28, 2026 |
| CVE-2026-56854 | HIGH | 7.5 | The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for … | Aug 28, 2026 |
| CVE-2026-50979 | HIGH | 8.1 | A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the … | Aug 28, 2026 |
| CVE-2026-4378 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects … | Aug 28, 2026 |
| CVE-2026-3423 | MEDIUM | 6.4 | The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, … | Aug 28, 2026 |
| CVE-2026-38725 | MEDIUM | 5.4 | xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input … | Aug 28, 2026 |
| CVE-2026-38638 | HIGH | 7.5 | An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 28, 2026 |
| CVE-2026-38636 | HIGH | 7.5 | An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 28, 2026 |
| CVE-2026-38093 | LOW | 3.3 | file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses … | Aug 28, 2026 |
| CVE-2026-37751 | CRITICAL | 9.8 | An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input. | Aug 28, 2026 |
| CVE-2026-37736 | HIGH | 7.5 | An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Aug 28, 2026 |
| CVE-2026-37710 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function | Aug 28, 2026 |
| CVE-2026-37237 | HIGH | 7.5 | vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py … | Aug 28, 2026 |
| CVE-2026-37236 | UNKNOWN | — | grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with … | Aug 28, 2026 |
| CVE-2026-19412 | UNKNOWN | — | This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical … | Aug 28, 2026 |
| CVE-2026-15603 | MEDIUM | 5.3 | morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize … | Aug 28, 2026 |
| CVE-2026-14942 | UNKNOWN | — | Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report … | Aug 28, 2026 |
| CVE-2026-13761 | UNKNOWN | — | Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial … | Aug 28, 2026 |
| CVE-2026-82261 | HIGH | 7.5 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send … | Aug 28, 2026 |
| CVE-2026-82260 | HIGH | 7.5 | SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form … | Aug 28, 2026 |
| CVE-2026-82259 | HIGH | 7.5 | SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions … | Aug 28, 2026 |
| CVE-2026-82258 | UNKNOWN | — | SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request … | Aug 28, 2026 |
| CVE-2026-82257 | MEDIUM | 4.3 | SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can … | Aug 28, 2026 |