Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

43670
Total
3528
Critical
13050
High
12909
Medium
CVE ID Severity Score Description Published
CVE-2026-16444 HIGH 7.5 Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations … Aug 26, 2026
CVE-2026-80237 HIGH 8.8 EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Authenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary … Aug 26, 2026
CVE-2026-80236 HIGH 8.2 Efence developed by Thinking Software Technology has a SQL Injection vulnerability. Unauthenticated remote attackers can access file upload functionality and read database contents. Aug 26, 2026
CVE-2026-80235 CRITICAL 9.8 EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary … Aug 26, 2026
CVE-2026-80234 MEDIUM 5.3 CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting … Aug 26, 2026
CVE-2026-80233 HIGH 7.2 CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web … Aug 26, 2026
CVE-2026-77533 CRITICAL 9.9 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute … Aug 26, 2026
CVE-2026-19538 UNKNOWN The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over … Aug 26, 2026
CVE-2026-19401 UNKNOWN Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of … Aug 26, 2026
CVE-2026-19197 MEDIUM 6.3 A user with organization administrator permissions can delete dashboard snapshots belonging to other organizations on the same Grafana instance, and can recover a snapshot's secret … Aug 26, 2026
CVE-2026-18916 UNKNOWN Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, … Aug 26, 2026
CVE-2026-18664 UNKNOWN When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian … Aug 26, 2026
CVE-2026-9668 MEDIUM 6.3 With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. This will consequently … Aug 26, 2026
CVE-2026-78237 HIGH 7.8 Insufficient input validation in ABR allows a low-privileged user to inject malicious entries into the sudoers file, resulting in persistent root access that remained effective … Aug 26, 2026
CVE-2026-78236 HIGH 8.8 An insecure PIN derivation mechanism in ABR allows a low-privileged user to escalate privileges to administrator by communicating over Cross-Process Communication (XPC) while masquerading as … Aug 26, 2026
CVE-2026-75977 HIGH 8.8 The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all versions up to, and including, 2.3.7. This … Aug 26, 2026
CVE-2026-6178 MEDIUM 6.4 The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's 'icon_box_2' shortcode in all versions up to, and including, 28.4 due … Aug 26, 2026
CVE-2026-18884 HIGH 7.5 The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Parameters in all versions up to, and including, … Aug 26, 2026
CVE-2026-58108 UNKNOWN The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no join between them. SQLAlchemy resolves that as an … Aug 26, 2026
CVE-2026-3002 MEDIUM 6.4 The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the multiple blocks in all … Aug 26, 2026
CVE-2026-18431 CRITICAL 9.8 The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is … Aug 26, 2026
CVE-2026-18331 HIGH 7.2 The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Aug 26, 2026
CVE-2026-15366 UNKNOWN A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly within the page Aug 26, 2026
CVE-2026-15365 UNKNOWN A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps outside the app. Aug 26, 2026
CVE-2026-79654 MEDIUM 4.3 A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the … Aug 26, 2026