Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44727
Total
3597
Critical
13286
High
13138
Medium
CVE ID Severity Score Description Published
CVE-2026-10618 MEDIUM 5.4 Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendered HTML without escaping them. New in markup/internal/attributes/attributes.go converts every … Aug 24, 2026
CVE-2026-10582 HIGH 7.4 Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the … Aug 24, 2026
CVE-2026-78317 HIGH 8.8 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. Aug 24, 2026
CVE-2026-78316 HIGH 8.8 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. Aug 24, 2026
CVE-2026-78315 HIGH 8.8 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. Aug 24, 2026
CVE-2026-78314 HIGH 8.8 SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution. Aug 24, 2026
CVE-2026-75975 HIGH 7.5 fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text … Aug 24, 2026
CVE-2026-75931 HIGH 7.5 fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a … Aug 24, 2026
CVE-2026-75899 HIGH 7.5 fast-uri is a URI parser for Node.js. It decodes percent escapes in a hostname during parsing and then decodes the parsed hostname a second time … Aug 24, 2026
CVE-2026-66897 CRITICAL 9.9 A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite … Aug 24, 2026
CVE-2026-16249 UNKNOWN Rejected reason: This CVE ID is a duplicate of CVE-2026-15303 and was never published. Both IDs were assigned to the same vulnerability in the 6Storage … Aug 24, 2026
CVE-2026-78321 UNKNOWN The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An attacker with access to the drone's … Aug 24, 2026
CVE-2026-78306 UNKNOWN DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth range to modify Wi-Fi configuration parameters, including the SSID, … Aug 24, 2026
CVE-2026-78255 UNKNOWN The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authenticating the requesting client. Filenames follow a … Aug 24, 2026
CVE-2026-77994 UNKNOWN Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to … Aug 24, 2026
CVE-2026-77993 UNKNOWN Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a reflected … Aug 24, 2026
CVE-2026-8173 MEDIUM 5.3 The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an authenticated administrator uses the 'Copy learned … Aug 24, 2026
CVE-2026-78202 HIGH 7.3 A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results … Aug 24, 2026
CVE-2026-78201 HIGH 7.3 A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the … Aug 24, 2026
CVE-2026-78200 MEDIUM 6.3 A flaw has been found in itsourcecode Library Management System 1.0. The affected element is an unknown function of the file editbooks.php. Executing a manipulation … Aug 24, 2026
CVE-2026-78199 HIGH 7.3 A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of … Aug 24, 2026
CVE-2026-78198 HIGH 7.3 A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such … Aug 24, 2026
CVE-2026-78197 HIGH 7.3 A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of … Aug 24, 2026
CVE-2026-78196 MEDIUM 4.4 A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component Android … Aug 24, 2026
CVE-2026-78187 LOW 3.1 A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang … Aug 24, 2026