Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43590
Total
3522
Critical
13030
High
12889
Medium
CVE ID Severity Score Description Published
CVE-2026-77507 MEDIUM 5.3 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the … Aug 26, 2026
CVE-2026-75415 UNKNOWN AntFlow V2.0.0 is vulnerable to Incorrect Access Control. JiMuMDCCommonsRequestLoggingFilter.java retrieves the userid from the request header as the core of the identity verification mechanism, allowing … Aug 26, 2026
CVE-2026-75414 UNKNOWN In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. Aug 26, 2026
CVE-2026-75413 UNKNOWN DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any … Aug 26, 2026
CVE-2026-75411 UNKNOWN JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs … Aug 26, 2026
CVE-2026-75364 UNKNOWN Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via … Aug 26, 2026
CVE-2026-75363 UNKNOWN An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n. Aug 26, 2026
CVE-2026-62326 MEDIUM 6.5 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role … Aug 26, 2026
CVE-2026-62249 MEDIUM 4.3 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project … Aug 26, 2026
CVE-2026-61792 HIGH 7.7 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their … Aug 26, 2026
CVE-2026-61790 MEDIUM 4.4 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure … Aug 26, 2026
CVE-2026-55228 HIGH 8.1 Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the … Aug 26, 2026
CVE-2026-55227 MEDIUM 4.3 Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the … Aug 26, 2026
CVE-2026-52473 UNKNOWN An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder. Aug 26, 2026
CVE-2026-52103 UNKNOWN A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context … Aug 26, 2026
CVE-2026-39275 UNKNOWN Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components. Aug 26, 2026
CVE-2026-15973 UNKNOWN LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission … Aug 26, 2026
CVE-2025-61480 UNKNOWN An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP … Aug 26, 2026
CVE-2025-61479 UNKNOWN An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC … Aug 26, 2026
CVE-2025-61478 UNKNOWN An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN … Aug 26, 2026
CVE-2025-51679 UNKNOWN An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior. Aug 26, 2026
CVE-2025-51675 UNKNOWN An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial … Aug 26, 2026
CVE-2026-79939 MEDIUM 5.8 Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially … Aug 26, 2026
CVE-2026-79938 HIGH 7.6 Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, … Aug 26, 2026
CVE-2026-77652 HIGH 7.8 A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette … Aug 26, 2026