Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44727
Total
3597
Critical
13286
High
13138
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-78186 | MEDIUM | 4.3 | A flaw has been found in Open5GS up to 2.8.0. This affects an unknown function of the file src/hss/hss-cx-path.c of the component HSS. This manipulation … | Aug 24, 2026 |
| CVE-2026-59561 | HIGH | 7.8 | Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victim user is directed to edit a file in … | Aug 24, 2026 |
| CVE-2026-78213 | HIGH | 8.7 | Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary … | Aug 24, 2026 |
| CVE-2026-78212 | HIGH | 7.5 | 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to … | Aug 24, 2026 |
| CVE-2026-78211 | CRITICAL | 9.8 | 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb … | Aug 24, 2026 |
| CVE-2026-78185 | MEDIUM | 6.3 | A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit.php. The manipulation of … | Aug 24, 2026 |
| CVE-2026-78182 | HIGH | 7.3 | A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The affected element is the function PlanController.getImmediatePlans … | Aug 24, 2026 |
| CVE-2026-78181 | HIGH | 7.3 | A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can … | Aug 24, 2026 |
| CVE-2026-78180 | HIGH | 7.3 | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component … | Aug 24, 2026 |
| CVE-2026-78179 | MEDIUM | 6.3 | A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard … | Aug 24, 2026 |
| CVE-2026-19853 | MEDIUM | 5.3 | NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific functionality to send emails to anyone on behalf … | Aug 24, 2026 |
| CVE-2026-19852 | MEDIUM | 6.1 | NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, including malicious HTML files, thereby achieving effects … | Aug 24, 2026 |
| CVE-2026-19200 | HIGH | 8.9 | The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL … | Aug 24, 2026 |
| CVE-2026-78178 | HIGH | 7.3 | A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of … | Aug 24, 2026 |
| CVE-2026-78177 | MEDIUM | 4.5 | A vulnerability was found in TanStack devtools-vite 0.7.0. Affected by this issue is the function installPackage of the file packages/devtools-bundler-core/src/package-manager.ts of the component Development Devtools … | Aug 24, 2026 |
| CVE-2026-78171 | HIGH | 7.3 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The … | Aug 24, 2026 |
| CVE-2026-78170 | HIGH | 8.8 | A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of … | Aug 24, 2026 |
| CVE-2026-78169 | CRITICAL | 9.9 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request … | Aug 24, 2026 |
| CVE-2026-78168 | CRITICAL | 9.8 | A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such … | Aug 24, 2026 |
| CVE-2026-78167 | CRITICAL | 10.0 | A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation … | Aug 24, 2026 |
| CVE-2026-78166 | MEDIUM | 6.3 | A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the … | Aug 24, 2026 |
| CVE-2026-78209 | HIGH | 8.2 | exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence … | Aug 24, 2026 |
| CVE-2026-78208 | HIGH | 7.5 | exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to … | Aug 24, 2026 |
| CVE-2026-78207 | CRITICAL | 9.4 | exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. … | Aug 24, 2026 |
| CVE-2026-78206 | HIGH | 7.5 | exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload … | Aug 24, 2026 |