Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43798
Total
3549
Critical
13122
High
12955
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77548 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute … | Aug 26, 2026 |
| CVE-2026-77547 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute … | Aug 26, 2026 |
| CVE-2026-77546 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute … | Aug 26, 2026 |
| CVE-2026-77532 | CRITICAL | 9.6 | A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote … | Aug 26, 2026 |
| CVE-2026-5092 | MEDIUM | 6.4 | The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customapi action handler in versions up … | Aug 26, 2026 |
| CVE-2026-3235 | MEDIUM | 5.3 | The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' … | Aug 26, 2026 |
| CVE-2026-18080 | CRITICAL | 9.8 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up … | Aug 26, 2026 |
| CVE-2026-80350 | HIGH | 7.1 | OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for … | Aug 26, 2026 |
| CVE-2026-80349 | CRITICAL | 9.8 | TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which … | Aug 26, 2026 |
| CVE-2026-80348 | HIGH | 8.8 | TarsWeb enforces its per-application roles by calling AuthService from individual controller methods, and four methods in app/controller/patch/PatchController.js make no such call. uploadAndPublish accepts a package … | Aug 26, 2026 |
| CVE-2026-80347 | HIGH | 7.5 | mcp-fetch checks a fetch target against its SSRF guard without removing the brackets that surround an IPv6 literal. isSafeUrl reads the hostname from the parsed … | Aug 26, 2026 |
| CVE-2026-80346 | HIGH | 7.1 | StarRocks performs no privilege check when a legacy synchronous materialized view is dropped. Every other statement type routed through AuthorizerStmtVisitor calls into Authorizer before execution, … | Aug 26, 2026 |
| CVE-2026-77545 | CRITICAL | 9.0 | A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices … | Aug 26, 2026 |
| CVE-2026-77543 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute … | Aug 26, 2026 |
| CVE-2026-77542 | CRITICAL | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute … | Aug 26, 2026 |
| CVE-2026-77541 | CRITICAL | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate … | Aug 26, 2026 |
| CVE-2026-77540 | CRITICAL | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute … | Aug 26, 2026 |
| CVE-2026-77539 | CRITICAL | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute … | Aug 26, 2026 |
| CVE-2026-77538 | HIGH | 8.2 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to escalate privileges within the … | Aug 26, 2026 |
| CVE-2026-77537 | CRITICAL | 10.0 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection … | Aug 26, 2026 |
| CVE-2026-77536 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS … | Aug 26, 2026 |
| CVE-2026-77535 | CRITICAL | 9.1 | A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute … | Aug 26, 2026 |
| CVE-2026-77534 | CRITICAL | 9.9 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS … | Aug 26, 2026 |
| CVE-2026-59683 | CRITICAL | 9.8 | The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise … | Aug 26, 2026 |
| CVE-2026-59682 | CRITICAL | 9.1 | Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3. | Aug 26, 2026 |