Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44043
Total
3569
Critical
13212
High
13018
Medium
CVE ID Severity Score Description Published
CVE-2026-32561 HIGH 8.8 Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions. Aug 24, 2026
CVE-2026-32560 HIGH 8.8 Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator <= 1.4 versions. Aug 24, 2026
CVE-2026-32559 CRITICAL 9.9 Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions. Aug 24, 2026
CVE-2026-32556 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions. Aug 24, 2026
CVE-2026-32555 CRITICAL 9.3 Unauthenticated SQL Injection in Boost <= 2.0.4 versions. Aug 24, 2026
CVE-2026-32554 CRITICAL 9.3 Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions. Aug 24, 2026
CVE-2026-27364 MEDIUM 6.5 Subscriber Broken Access Control in Style Kits <= 2.6.5 versions. Aug 24, 2026
CVE-2026-17113 MEDIUM 6.0 A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI … Aug 24, 2026
CVE-2026-7455 HIGH 7.8 A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to … Aug 24, 2026
CVE-2026-77635 UNKNOWN CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable … Aug 24, 2026
CVE-2026-77634 UNKNOWN CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers … Aug 24, 2026
CVE-2026-77567 HIGH 8.1 Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication … Aug 24, 2026
CVE-2026-75554 UNKNOWN Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from an organization to keep reading its private … Aug 24, 2026
CVE-2026-75542 UNKNOWN Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositories permission to read another organization's private packages. … Aug 24, 2026
CVE-2026-75464 UNKNOWN OneNav 1.2.4 contains an authenticated arbitrary file deletion vulnerability via import_link(). Aug 24, 2026
CVE-2026-5006 MEDIUM 6.8 A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may manipulate an identity value referenced by a templated … Aug 24, 2026
CVE-2026-56136 UNKNOWN In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read possibly confidential information in an ntfs-3g process … Aug 24, 2026
CVE-2026-56135 UNKNOWN In NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the function build_inherited_id() in libntfs-3g/security.c that allows an attacker to corrupt heap memory in the … Aug 24, 2026
CVE-2026-55468 MEDIUM 4.3 Wagtail is an open source content management system built on Django. Prior to versions 7.0.9, 7.3.4, 7.4.3, and 8.0rc2 on their respective release lines, the … Aug 24, 2026
CVE-2026-52492 UNKNOWN An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based … Aug 24, 2026
CVE-2026-52490 UNKNOWN An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c Aug 24, 2026
CVE-2026-19568 HIGH 7.8 A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to … Aug 24, 2026
CVE-2026-16783 HIGH 7.8 A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to … Aug 24, 2026
CVE-2026-16782 MEDIUM 5.3 A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to … Aug 24, 2026
CVE-2026-16781 MEDIUM 5.5 A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to … Aug 24, 2026