Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
43999
Total
3569
Critical
13202
High
13005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48424 | HIGH | 7.8 | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-48423 | HIGH | 7.8 | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-48422 | HIGH | 7.8 | Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-48421 | HIGH | 7.8 | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Aug 25, 2026 |
| CVE-2026-48420 | HIGH | 7.8 | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Aug 25, 2026 |
| CVE-2026-48419 | HIGH | 7.8 | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Aug 25, 2026 |
| CVE-2026-48418 | HIGH | 7.8 | Substance3D - Sampler is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation … | Aug 25, 2026 |
| CVE-2026-48417 | HIGH | 7.8 | Substance3D - Sampler is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. … | Aug 25, 2026 |
| CVE-2026-26211 | MEDIUM | 4.8 | Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three … | Aug 25, 2026 |
| CVE-2026-78468 | MEDIUM | 6.5 | The FluentCRM Pro – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to SQL Injection in … | Aug 25, 2026 |
| CVE-2026-75498 | HIGH | 7.2 | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to … | Aug 25, 2026 |
| CVE-2026-75497 | HIGH | 7.2 | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to … | Aug 25, 2026 |
| CVE-2026-75496 | HIGH | 7.2 | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, … | Aug 25, 2026 |
| CVE-2026-64204 | HIGH | 7.8 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … | Aug 25, 2026 |
| CVE-2026-64203 | HIGH | 7.8 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … | Aug 25, 2026 |
| CVE-2026-64202 | HIGH | 7.8 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … | Aug 25, 2026 |
| CVE-2026-64201 | HIGH | 7.8 | There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution. Successful exploitation requires an … | Aug 25, 2026 |
| CVE-2026-59189 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 … | Aug 25, 2026 |
| CVE-2026-59187 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and … | Aug 25, 2026 |
| CVE-2026-59186 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through … | Aug 25, 2026 |
| CVE-2026-59184 | HIGH | 7.1 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, … | Aug 25, 2026 |
| CVE-2026-55585 | HIGH | 8.8 | QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, … | Aug 25, 2026 |
| CVE-2026-55571 | HIGH | 8.2 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a … | Aug 25, 2026 |
| CVE-2026-55557 | UNKNOWN | — | browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the … | Aug 25, 2026 |
| CVE-2026-55553 | HIGH | 7.5 | urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through … | Aug 25, 2026 |