Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

42900
Total
3476
Critical
12865
High
12603
Medium
CVE ID Severity Score Description Published
CVE-2026-51106 UNKNOWN An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.cpp component Aug 26, 2026
CVE-2026-48786 MEDIUM 6.5 Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll … Aug 26, 2026
CVE-2026-41262 MEDIUM 4.3 Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify … Aug 26, 2026
CVE-2026-36851 UNKNOWN Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration. Aug 26, 2026
CVE-2026-19485 UNKNOWN A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versions prior to 2026-04-27 on Google Cloud Platform … Aug 26, 2026
CVE-2025-61165 UNKNOWN An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. Aug 26, 2026
CVE-2025-61164 UNKNOWN Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. Aug 26, 2026
CVE-2025-61163 UNKNOWN Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin … Aug 26, 2026
CVE-2025-61162 UNKNOWN Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint Aug 26, 2026
CVE-2026-76784 UNKNOWN Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communication protocol. An adjacent network attacker may intercept, replay or forge … Aug 26, 2026
CVE-2026-58474 HIGH 8.8 whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to … Aug 26, 2026
CVE-2026-54256 MEDIUM 5.4 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend FileUpload form widget … Aug 26, 2026
CVE-2026-47841 HIGH 7.4 An application using Spring Security's WebAuthn support may be vulnerable to user verification bypass when using a distributed HTTP session store. Spring Security 7.1.0 Spring … Aug 26, 2026
CVE-2026-47837 MEDIUM 6.8 Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This … Aug 26, 2026
CVE-2026-47836 HIGH 7.2 The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config … Aug 26, 2026
CVE-2026-32639 MEDIUM 6.8 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the CMS section's Theme Editor … Aug 26, 2026
CVE-2026-32593 MEDIUM 5.9 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is … Aug 26, 2026
CVE-2025-56798 UNKNOWN Cross-Site Request Forgery (CSRF) vulnerability in Lime Technology, Inc.'s Unraid OS version 6.12.14 and earlier allows remote attackers to escalate privileges via the Unraid authentication … Aug 26, 2026
CVE-2025-29419 UNKNOWN CTFd v3.7.6 was discovered to be vulnerable to a man-in-the-middle attack. Aug 26, 2026
CVE-2023-42179 UNKNOWN Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process. Aug 26, 2026
CVE-2026-80153 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 26, 2026
CVE-2026-35445 UNKNOWN Winter CMS is a content management system built on the Laravel PHP framework. In versions prior to 1.2.13, the backend did not validate the handler … Aug 26, 2026
CVE-2026-32258 HIGH 8.1 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor … Aug 26, 2026
CVE-2026-32257 HIGH 8.1 Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings … Aug 26, 2026
CVE-2020-15878 UNKNOWN An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a … Aug 26, 2026