Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
11702
Total
781
Critical
3315
High
3732
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-13890 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12494. Reason: This candidate is a reservation duplicate of CVE-2025-12494. Notes: All CVE … | Apr 30, 2026 |
| CVE-2026-7500 | MEDIUM | 5.4 | When Keycloak is started with `--features-disabled=account,account-api`, the Account REST API is only partially disabled. Five endpoints under the versioned path `/account/v1alpha1` remain fully functional — … | Apr 30, 2026 |
| CVE-2026-36959 | HIGH | 7.5 | U-SPEED N300 router V1.0.0 does not implement rate limiting or account lockout protections on the /api/login endpoint. This allows an attacker on the local network … | Apr 30, 2026 |
| CVE-2026-36958 | HIGH | 7.5 | A denial-of-service vulnerability exists in the U-SPEED N300 V1.0.0 wireless router. By sending a large number of concurrent HTTP requests to random or non-existent endpoints … | Apr 30, 2026 |
| CVE-2026-36957 | HIGH | 7.5 | Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router V1.0.0 is vulnerable to Denial of Service via the boa web server URI handler. By initiating … | Apr 30, 2026 |
| CVE-2026-36956 | HIGH | 8.8 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the Dbit N300 T1 Pro wireless router V1.0.0. The router fails to … | Apr 30, 2026 |
| CVE-2026-7246 | HIGH | 7.2 | Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged … | Apr 30, 2026 |
| CVE-2026-7163 | MEDIUM | 6.1 | A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped … | Apr 30, 2026 |
| CVE-2026-2892 | HIGH | 7.5 | The Otter Blocks plugin for WordPress is vulnerable to Purchase Verification Bypass in all versions up to, and including, 3.1.4. This is due to the … | Apr 30, 2026 |
| CVE-2026-7402 | HIGH | 8.1 | Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. | Apr 30, 2026 |
| CVE-2026-7399 | HIGH | 8.1 | Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117. | Apr 30, 2026 |
| CVE-2026-7382 | MEDIUM | 6.5 | Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows … | Apr 30, 2026 |
| CVE-2025-14576 | UNKNOWN | — | Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt … | Apr 30, 2026 |
| CVE-2024-13971 | UNKNOWN | — | Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to … | Apr 30, 2026 |
| CVE-2026-5080 | MEDIUM | 5.9 | Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with … | Apr 30, 2026 |
| CVE-2026-41882 | HIGH | 7.4 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | Apr 30, 2026 |
| CVE-2026-31693 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a … | Apr 30, 2026 |
| CVE-2026-1493 | UNKNOWN | — | LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker … | Apr 30, 2026 |
| CVE-2026-31787 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor … | Apr 30, 2026 |
| CVE-2026-31786 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL terminated nor … | Apr 30, 2026 |
| CVE-2026-31692 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on … | Apr 30, 2026 |
| CVE-2026-6498 | MEDIUM | 5.3 | The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 … | Apr 30, 2026 |
| CVE-2026-42800 | HIGH | 7.4 | NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/sipuri.c. | Apr 30, 2026 |
| CVE-2026-41016 | MEDIUM | 5.9 | Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between … | Apr 30, 2026 |
| CVE-2026-42799 | HIGH | 7.4 | Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects Kestrel: before 2026/02/10. | Apr 30, 2026 |