Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43670
Total
3528
Critical
13050
High
12909
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-16444 | HIGH | 7.5 | Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations … | Aug 26, 2026 |
| CVE-2026-80237 | HIGH | 8.8 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary … | Aug 26, 2026 |
| CVE-2026-80236 | HIGH | 8.2 | Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents. | Aug 26, 2026 |
| CVE-2026-80235 | CRITICAL | 9.8 | EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary … | Aug 26, 2026 |
| CVE-2026-80234 | MEDIUM | 5.3 | CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting … | Aug 26, 2026 |
| CVE-2026-80233 | HIGH | 7.2 | CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web … | Aug 26, 2026 |
| CVE-2026-77533 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute … | Aug 26, 2026 |
| CVE-2026-19538 | UNKNOWN | — | The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over … | Aug 26, 2026 |
| CVE-2026-19401 | UNKNOWN | — | Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of … | Aug 26, 2026 |
| CVE-2026-19197 | MEDIUM | 6.3 | A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret … | Aug 26, 2026 |
| CVE-2026-18916 | UNKNOWN | — | Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, … | Aug 26, 2026 |
| CVE-2026-18664 | UNKNOWN | — | When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian … | Aug 26, 2026 |
| CVE-2026-9668 | MEDIUM | 6.3 | With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently … | Aug 26, 2026 |
| CVE-2026-78237 | HIGH | 7.8 | Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective … | Aug 26, 2026 |
| CVE-2026-78236 | HIGH | 8.8 | An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as … | Aug 26, 2026 |
| CVE-2026-75977 | HIGH | 8.8 | The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This … | Aug 26, 2026 |
| CVE-2026-6178 | MEDIUM | 6.4 | The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's 'icon_box_2' shortcode in all versions up to, and including, 28.4 due … | Aug 26, 2026 |
| CVE-2026-18884 | HIGH | 7.5 | The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, … | Aug 26, 2026 |
| CVE-2026-58108 | UNKNOWN | — | The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an … | Aug 26, 2026 |
| CVE-2026-3002 | MEDIUM | 6.4 | The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all … | Aug 26, 2026 |
| CVE-2026-18431 | CRITICAL | 9.8 | The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is … | Aug 26, 2026 |
| CVE-2026-18331 | HIGH | 7.2 | The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | Aug 26, 2026 |
| CVE-2026-15366 | UNKNOWN | — | A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page | Aug 26, 2026 |
| CVE-2026-15365 | UNKNOWN | — | A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app. | Aug 26, 2026 |
| CVE-2026-79654 | MEDIUM | 4.3 | A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the … | Aug 26, 2026 |