Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41921
Total
3420
Critical
12394
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85618 | MEDIUM | 6.5 | ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input … | Sep 04, 2026 |
| CVE-2026-85608 | HIGH | 7.5 | Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying … | Sep 04, 2026 |
| CVE-2026-85607 | HIGH | 8.8 | Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these procedures … | Sep 04, 2026 |
| CVE-2026-85606 | HIGH | 7.5 | firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply … | Sep 04, 2026 |
| CVE-2026-85605 | MEDIUM | 5.3 | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. … | Sep 04, 2026 |
| CVE-2026-82729 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. … | Sep 04, 2026 |
| CVE-2026-82728 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause … | Sep 04, 2026 |
| CVE-2026-81859 | MEDIUM | 6.2 | CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm. | Sep 04, 2026 |
| CVE-2026-81832 | HIGH | 7.7 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to … | Sep 04, 2026 |
| CVE-2026-6958 | HIGH | 7.8 | Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary … | Sep 04, 2026 |
| CVE-2026-19727 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library … | Sep 04, 2026 |
| CVE-2026-19205 | HIGH | 7.5 | Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026. | Sep 04, 2026 |
| CVE-2026-14466 | MEDIUM | 4.3 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some … | Sep 04, 2026 |
| CVE-2026-85522 | MEDIUM | 5.3 | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component … | Sep 04, 2026 |
| CVE-2026-85517 | MEDIUM | 5.3 | A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component … | Sep 04, 2026 |
| CVE-2026-77818 | MEDIUM | 6.1 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library … | Sep 04, 2026 |
| CVE-2026-52691 | UNKNOWN | — | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. This … | Sep 04, 2026 |
| CVE-2026-19081 | MEDIUM | 4.3 | Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and … | Sep 04, 2026 |
| CVE-2026-19057 | MEDIUM | 5.4 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects … | Sep 04, 2026 |
| CVE-2026-12483 | HIGH | 7.5 | The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient … | Sep 04, 2026 |
| CVE-2026-85649 | HIGH | 7.9 | (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. … | Sep 04, 2026 |
| CVE-2026-85516 | HIGH | 7.3 | A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of … | Sep 04, 2026 |
| CVE-2026-85514 | MEDIUM | 6.3 | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API … | Sep 04, 2026 |
| CVE-2026-85513 | MEDIUM | 6.3 | A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp … | Sep 04, 2026 |
| CVE-2026-82309 | UNKNOWN | — | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names … | Sep 04, 2026 |