Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43590
Total
3522
Critical
13030
High
12889
Medium
CVE ID Severity Score Description Published
CVE-2026-77611 HIGH 7.1 SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested … Aug 26, 2026
CVE-2026-77368 HIGH 7.6 SeaweedFS is a distributed storage system for files and blobs. In version 4.39, the filer's TUS resumable-upload handler checks JWT allowed_prefixes scoping only when a … Aug 26, 2026
CVE-2026-77317 HIGH 8.1 SeaweedFS is a distributed storage system for files and blobs. In versions from 3.88 through 4.39, the SFTP server evaluates configured path permissions with a … Aug 26, 2026
CVE-2026-77298 UNKNOWN SeaweedFS is a distributed storage system for files and blobs. In versions 4.39 and earlier, the S3 API accepts an external OIDC JWT sent directly … Aug 26, 2026
CVE-2026-75333 UNKNOWN yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path … Aug 26, 2026
CVE-2026-75331 UNKNOWN tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type … Aug 26, 2026
CVE-2026-75329 UNKNOWN The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project … Aug 26, 2026
CVE-2026-75328 UNKNOWN In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability: Aug 26, 2026
CVE-2026-65930 UNKNOWN LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5. Aug 26, 2026
CVE-2026-65647 UNKNOWN Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root. Aug 26, 2026
CVE-2026-65646 UNKNOWN Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges. Aug 26, 2026
CVE-2026-65642 UNKNOWN Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases. Aug 26, 2026
CVE-2026-65641 UNKNOWN A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. Aug 26, 2026
CVE-2026-64632 UNKNOWN A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account. Aug 26, 2026
CVE-2026-63360 UNKNOWN LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the … Aug 26, 2026
CVE-2026-61617 HIGH 7.7 Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not … Aug 26, 2026
CVE-2026-58070 UNKNOWN A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that … Aug 26, 2026
CVE-2026-55182 UNKNOWN LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli … Aug 26, 2026
CVE-2026-45694 MEDIUM 5.4 LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the … Aug 26, 2026
CVE-2026-43621 NONE Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to … Aug 26, 2026
CVE-2026-21810 MEDIUM 4.4 HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to … Aug 26, 2026
CVE-2026-21809 LOW 3.9 HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an … Aug 26, 2026
CVE-2026-16809 UNKNOWN LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage … Aug 26, 2026
CVE-2026-79921 UNKNOWN amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a compromised or malicious AMQP broker can force the client to allocate resources for and … Aug 26, 2026
CVE-2026-77573 LOW 3.5 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs … Aug 26, 2026