Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42900
Total
3476
Critical
12865
High
12603
Medium
CVE ID Severity Score Description Published
CVE-2026-39275 UNKNOWN Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components. Aug 26, 2026
CVE-2026-15973 UNKNOWN LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission … Aug 26, 2026
CVE-2025-61480 UNKNOWN An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP … Aug 26, 2026
CVE-2025-61479 UNKNOWN An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC … Aug 26, 2026
CVE-2025-61478 UNKNOWN An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN … Aug 26, 2026
CVE-2025-51679 UNKNOWN An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. Aug 26, 2026
CVE-2025-51675 UNKNOWN An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial … Aug 26, 2026
CVE-2026-79939 MEDIUM 5.8 Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially … Aug 26, 2026
CVE-2026-79938 HIGH 7.6 Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, … Aug 26, 2026
CVE-2026-77652 HIGH 7.8 A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette … Aug 26, 2026
CVE-2026-77508 LOW 3.5 Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to … Aug 26, 2026
CVE-2026-75601 MEDIUM 4.3 Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features … Aug 26, 2026
CVE-2026-75334 UNKNOWN The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through … Aug 26, 2026
CVE-2026-75327 UNKNOWN In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability: Aug 26, 2026
CVE-2026-74774 MEDIUM 5.9 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … Aug 26, 2026
CVE-2026-74771 MEDIUM 6.5 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit … Aug 26, 2026
CVE-2026-74770 HIGH 8.8 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low … Aug 26, 2026
CVE-2026-71172 MEDIUM 4.3 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit … Aug 26, 2026
CVE-2026-71054 MEDIUM 6.5 Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network … Aug 26, 2026
CVE-2026-68863 HIGH 7.5 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading … Aug 26, 2026
CVE-2026-68861 HIGH 8.8 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low … Aug 26, 2026
CVE-2026-68000 UNKNOWN The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through … Aug 26, 2026
CVE-2026-67275 MEDIUM 5.3 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this … Aug 26, 2026
CVE-2026-66003 UNKNOWN Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows … Aug 26, 2026
CVE-2026-60004 CRITICAL 9.8 Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. Aug 26, 2026