Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43590
Total
3522
Critical
13030
High
12889
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-81562 | MEDIUM | 5.3 | A security flaw has been discovered in AlexGladkov claude-in-mobile 3.10.2. This affects the function execSync of the file src/adb/client.ts. Performing a manipulation results in os … | Aug 27, 2026 |
| CVE-2026-81560 | MEDIUM | 5.3 | A vulnerability was identified in blackms aistack up to 1.6.1. Affected by this issue is some unknown functionality of the file src/web/server.ts of the component … | Aug 27, 2026 |
| CVE-2026-74233 | CRITICAL | 9.8 | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, … | Aug 27, 2026 |
| CVE-2026-74232 | CRITICAL | 9.8 | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, … | Aug 27, 2026 |
| CVE-2026-66155 | HIGH | 7.6 | A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions … | Aug 27, 2026 |
| CVE-2026-5218 | MEDIUM | 4.3 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Softtr Informatics Technology Trading Limited Company E-Commerce Pack allows Cross-Site Scripting … | Aug 27, 2026 |
| CVE-2026-17562 | MEDIUM | 6.5 | Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AdisyonPro: before v5.21.0. | Aug 27, 2026 |
| CVE-2026-81625 | HIGH | 8.8 | A remote attacker with user privileges may use a malicious or compromised NASL vulnerability test (VT) on the affected products to trigger a stack buffer … | Aug 27, 2026 |
| CVE-2026-81581 | HIGH | 8.8 | Improper validation of memory boundaries in WibuKey64.sys of WibuKey up to 6.70 for Windows can be exploited by an attacker by setting the pointers outside … | Aug 27, 2026 |
| CVE-2026-81579 | HIGH | 8.8 | In WibuKey for Windows before version 6.71, an untrusted pointer dereference in the WibuKey2_64.sys kernel driver for 64-bit Windows allows an attacker to exploit a … | Aug 27, 2026 |
| CVE-2026-81576 | HIGH | 7.7 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 issues handles per connection and relies on a cryptographically weak SID as sole … | Aug 27, 2026 |
| CVE-2026-81575 | HIGH | 7.5 | If configured as a server, CodeMeter Runtime before versions 8.41a and 9.10 accepts requests with opcode 0x5e, which contain the data length and the data … | Aug 27, 2026 |
| CVE-2026-81574 | HIGH | 8.2 | In CodeMeter Runtime before versions 8.41a and 9.10, the logger does not sanitize input strings in certain cases, allowing an attacker to inject printf-style format … | Aug 27, 2026 |
| CVE-2026-81573 | HIGH | 8.6 | If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only … | Aug 27, 2026 |
| CVE-2026-81572 | HIGH | 7.8 | cmu.exe --create-io --file C: creates a predictable temporary file under C:\CM-Stick. The directory and file paths are not properly checked for NTFS reparse points, such … | Aug 27, 2026 |
| CVE-2026-81279 | MEDIUM | 5.4 | Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions. | Aug 27, 2026 |
| CVE-2026-81277 | HIGH | 8.5 | Contributor SQL Injection in Suggestion Engine for WooCommerce <= 2.0.11 versions. | Aug 27, 2026 |
| CVE-2026-81276 | MEDIUM | 5.3 | Unauthenticated Broken Access Control in Kali Forms <= 2.4.23 versions. | Aug 27, 2026 |
| CVE-2026-81274 | MEDIUM | 5.3 | Subscriber Broken Access Control in Ditty <= 3.1.67 versions. | Aug 27, 2026 |
| CVE-2026-81273 | HIGH | 8.1 | Unauthenticated Cross Site Request Forgery (CSRF) in FluentBooking Pro <= 2.2.4 versions. | Aug 27, 2026 |
| CVE-2026-81272 | MEDIUM | 4.9 | Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions. | Aug 27, 2026 |
| CVE-2026-81271 | HIGH | 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions. | Aug 27, 2026 |
| CVE-2026-80433 | HIGH | 7.5 | Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions. | Aug 27, 2026 |
| CVE-2026-78293 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP w3all phpBB <= 3.0.6 versions. | Aug 27, 2026 |
| CVE-2026-78292 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions. | Aug 27, 2026 |