Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42900
Total
3476
Critical
12865
High
12603
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-75330 | CRITICAL | 9.8 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through … | Aug 26, 2026 |
| CVE-2026-69129 | UNKNOWN | — | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated … | Aug 26, 2026 |
| CVE-2026-65956 | UNKNOWN | — | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public … | Aug 26, 2026 |
| CVE-2026-47666 | HIGH | 7.6 | Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font … | Aug 26, 2026 |
| CVE-2026-47665 | HIGH | 8.7 | Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, … | Aug 26, 2026 |
| CVE-2026-21808 | MEDIUM | 4.1 | HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker … | Aug 26, 2026 |
| CVE-2026-21807 | LOW | 3.9 | HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow. | Aug 26, 2026 |
| CVE-2026-18823 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 26, 2026 |
| CVE-2025-62341 | LOW | 3.7 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allowing an attacker to send unauthorized requests in certain … | Aug 26, 2026 |
| CVE-2026-81202 | HIGH | 7.3 | A flaw has been found in itsourcecode Payroll System 1.0. The impacted element is the function create/read/update/delete of the file ajax.php of the component CRUD … | Aug 26, 2026 |
| CVE-2026-77611 | HIGH | 7.1 | SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested … | Aug 26, 2026 |
| CVE-2026-77368 | HIGH | 7.6 | SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a … | Aug 26, 2026 |
| CVE-2026-77317 | HIGH | 8.1 | SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a … | Aug 26, 2026 |
| CVE-2026-77298 | UNKNOWN | — | SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly … | Aug 26, 2026 |
| CVE-2026-75333 | UNKNOWN | — | yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path … | Aug 26, 2026 |
| CVE-2026-75331 | UNKNOWN | — | tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type … | Aug 26, 2026 |
| CVE-2026-75329 | UNKNOWN | — | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project … | Aug 26, 2026 |
| CVE-2026-75328 | UNKNOWN | — | In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability: | Aug 26, 2026 |
| CVE-2026-65930 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. | Aug 26, 2026 |
| CVE-2026-65647 | UNKNOWN | — | Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. | Aug 26, 2026 |
| CVE-2026-65646 | UNKNOWN | — | Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges. | Aug 26, 2026 |
| CVE-2026-65642 | UNKNOWN | — | Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases. | Aug 26, 2026 |
| CVE-2026-65641 | UNKNOWN | — | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. | Aug 26, 2026 |
| CVE-2026-64632 | UNKNOWN | — | A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account. | Aug 26, 2026 |
| CVE-2026-63360 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the … | Aug 26, 2026 |