Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42900
Total
3476
Critical
12865
High
12603
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-61617 | HIGH | 7.7 | Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not … | Aug 26, 2026 |
| CVE-2026-58070 | UNKNOWN | — | A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that … | Aug 26, 2026 |
| CVE-2026-55182 | UNKNOWN | — | LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli … | Aug 26, 2026 |
| CVE-2026-45694 | MEDIUM | 5.4 | LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the … | Aug 26, 2026 |
| CVE-2026-43621 | NONE | — | Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to … | Aug 26, 2026 |
| CVE-2026-21810 | MEDIUM | 4.4 | HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to … | Aug 26, 2026 |
| CVE-2026-21809 | LOW | 3.9 | HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an … | Aug 26, 2026 |
| CVE-2026-16809 | UNKNOWN | — | LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage … | Aug 26, 2026 |
| CVE-2026-79921 | UNKNOWN | — | amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and … | Aug 26, 2026 |
| CVE-2026-77573 | LOW | 3.5 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs … | Aug 26, 2026 |
| CVE-2026-77507 | MEDIUM | 5.3 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the … | Aug 26, 2026 |
| CVE-2026-75415 | UNKNOWN | — | AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing … | Aug 26, 2026 |
| CVE-2026-75414 | UNKNOWN | — | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | Aug 26, 2026 |
| CVE-2026-75413 | UNKNOWN | — | DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any … | Aug 26, 2026 |
| CVE-2026-75411 | UNKNOWN | — | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs … | Aug 26, 2026 |
| CVE-2026-75364 | UNKNOWN | — | Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via … | Aug 26, 2026 |
| CVE-2026-75363 | UNKNOWN | — | An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n. | Aug 26, 2026 |
| CVE-2026-62326 | MEDIUM | 6.5 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role … | Aug 26, 2026 |
| CVE-2026-62249 | MEDIUM | 4.3 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project … | Aug 26, 2026 |
| CVE-2026-61792 | HIGH | 7.7 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their … | Aug 26, 2026 |
| CVE-2026-61790 | MEDIUM | 4.4 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure … | Aug 26, 2026 |
| CVE-2026-55228 | HIGH | 8.1 | Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the … | Aug 26, 2026 |
| CVE-2026-55227 | MEDIUM | 4.3 | Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the … | Aug 26, 2026 |
| CVE-2026-52473 | UNKNOWN | — | An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder. | Aug 26, 2026 |
| CVE-2026-52103 | UNKNOWN | — | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context … | Aug 26, 2026 |