Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41940
Total
3420
Critical
12400
High
12304
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-15691 | MEDIUM | 5.3 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying … | Sep 04, 2026 |
| CVE-2026-85509 | CRITICAL | 9.8 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. | Sep 04, 2026 |
| CVE-2026-85508 | CRITICAL | 9.8 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info). | Sep 04, 2026 |
| CVE-2026-85507 | CRITICAL | 9.8 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info). | Sep 04, 2026 |
| CVE-2026-85506 | CRITICAL | 9.8 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info). | Sep 04, 2026 |
| CVE-2026-85505 | HIGH | 7.5 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than … | Sep 04, 2026 |
| CVE-2026-85504 | CRITICAL | 9.8 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses. | Sep 04, 2026 |
| CVE-2026-85409 | MEDIUM | 6.3 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire Service. Such manipulation of the … | Sep 04, 2026 |
| CVE-2026-85408 | MEDIUM | 4.3 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation … | Sep 04, 2026 |
| CVE-2026-85407 | MEDIUM | 4.3 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. The … | Sep 04, 2026 |
| CVE-2026-11613 | CRITICAL | 9.8 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter … | Sep 04, 2026 |
| CVE-2026-85406 | LOW | 3.5 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross … | Sep 04, 2026 |
| CVE-2026-85405 | LOW | 3.5 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the … | Sep 04, 2026 |
| CVE-2026-85403 | HIGH | 7.3 | A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the … | Sep 04, 2026 |
| CVE-2026-85402 | HIGH | 7.3 | A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id … | Sep 04, 2026 |
| CVE-2026-85401 | MEDIUM | 6.3 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component … | Sep 04, 2026 |
| CVE-2026-85399 | HIGH | 7.3 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing … | Sep 04, 2026 |
| CVE-2026-85398 | HIGH | 7.3 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID … | Sep 04, 2026 |
| CVE-2026-85149 | MEDIUM | 5.3 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT … | Sep 04, 2026 |
| CVE-2026-85148 | CRITICAL | 9.8 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user … | Sep 04, 2026 |
| CVE-2026-85147 | HIGH | 7.5 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, … | Sep 04, 2026 |
| CVE-2026-85146 | CRITICAL | 9.8 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords … | Sep 04, 2026 |
| CVE-2026-75754 | UNKNOWN | — | Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the … | Sep 04, 2026 |
| CVE-2026-85397 | HIGH | 7.3 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search … | Sep 04, 2026 |
| CVE-2026-85383 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a … | Sep 04, 2026 |