Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44727
Total
3597
Critical
13286
High
13138
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10618 | MEDIUM | 5.4 | Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every … | Aug 24, 2026 |
| CVE-2026-10582 | HIGH | 7.4 | Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the … | Aug 24, 2026 |
| CVE-2026-78317 | HIGH | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | Aug 24, 2026 |
| CVE-2026-78316 | HIGH | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | Aug 24, 2026 |
| CVE-2026-78315 | HIGH | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | Aug 24, 2026 |
| CVE-2026-78314 | HIGH | 8.8 | SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. | Aug 24, 2026 |
| CVE-2026-75975 | HIGH | 7.5 | fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text … | Aug 24, 2026 |
| CVE-2026-75931 | HIGH | 7.5 | fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a … | Aug 24, 2026 |
| CVE-2026-75899 | HIGH | 7.5 | fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time … | Aug 24, 2026 |
| CVE-2026-66897 | CRITICAL | 9.9 | A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite … | Aug 24, 2026 |
| CVE-2026-16249 | UNKNOWN | — | Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage … | Aug 24, 2026 |
| CVE-2026-78321 | UNKNOWN | — | The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's … | Aug 24, 2026 |
| CVE-2026-78306 | UNKNOWN | — | DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, … | Aug 24, 2026 |
| CVE-2026-78255 | UNKNOWN | — | The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a … | Aug 24, 2026 |
| CVE-2026-77994 | UNKNOWN | — | Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to … | Aug 24, 2026 |
| CVE-2026-77993 | UNKNOWN | — | Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected … | Aug 24, 2026 |
| CVE-2026-8173 | MEDIUM | 5.3 | The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned … | Aug 24, 2026 |
| CVE-2026-78202 | HIGH | 7.3 | A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results … | Aug 24, 2026 |
| CVE-2026-78201 | HIGH | 7.3 | A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the … | Aug 24, 2026 |
| CVE-2026-78200 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation … | Aug 24, 2026 |
| CVE-2026-78199 | HIGH | 7.3 | A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of … | Aug 24, 2026 |
| CVE-2026-78198 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such … | Aug 24, 2026 |
| CVE-2026-78197 | HIGH | 7.3 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of … | Aug 24, 2026 |
| CVE-2026-78196 | MEDIUM | 4.4 | A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android … | Aug 24, 2026 |
| CVE-2026-78187 | LOW | 3.1 | A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang … | Aug 24, 2026 |