Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-76571 | UNKNOWN | — | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.3 - The condition parameter passed to a list … | Aug 22, 2026 |
| CVE-2026-74584 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to userspace bnxt_re_alloc_ucontext() allocates uctx->shpg via __get_free_page(GFP_KERNEL). The buddy … | Aug 22, 2026 |
| CVE-2026-70626 | MEDIUM | 6.2 | NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside the corpus root. The vulnerability … | Aug 22, 2026 |
| CVE-2026-6258 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 22, 2026 |
| CVE-2026-68768 | MEDIUM | 6.1 | hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a fixed-size buffer (HCBUFSIZ_LARGE, ~16 MB), the … | Aug 22, 2026 |
| CVE-2026-68767 | MEDIUM | 6.1 | hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer length. Attackers … | Aug 22, 2026 |
| CVE-2026-68766 | HIGH | 7.8 | hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and --potfile-path. Attackers can craft restore files … | Aug 22, 2026 |
| CVE-2026-66393 | HIGH | 7.5 | NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of service by supplying deeply nested JSON structures. … | Aug 22, 2026 |
| CVE-2026-65915 | MEDIUM | 6.5 | NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compares a normalized path against itself, making the security check … | Aug 22, 2026 |
| CVE-2026-63312 | HIGH | 7.5 | NLTK before 3.10.0 contains an arbitrary local file read vulnerability in StreamBackedCorpusView that bypasses pathsec.ENFORCE by calling builtins.open() directly instead of pathsec.open(). Attackers who control … | Aug 22, 2026 |
| CVE-2026-63311 | MEDIUM | 5.3 | NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the validate_network_url() function in nltk/pathsec.py. The _resolve_hostname() helper catches OSError … | Aug 22, 2026 |
| CVE-2026-63310 | HIGH | 7.1 | NLTK before 3.9.3 fails to verify file integrity after downloading packages and before extraction in the downloader module. Attackers can perform man-in-the-middle attacks or DNS … | Aug 22, 2026 |
| CVE-2026-62388 | HIGH | 7.5 | NLTK versions before 3.10.0 default to ENFORCE=False in pathsec.py, causing all security validation functions to emit warnings instead of raising exceptions. Attackers can bypass path … | Aug 22, 2026 |
| CVE-2026-62385 | MEDIUM | 5.9 | NLTK versions before 3.10.0 contain a path traversal vulnerability in FramenetCorpusReader and NKJPCorpusReader that allows attackers to parse XML files outside the corpus root by … | Aug 22, 2026 |
| CVE-2026-62384 | HIGH | 7.5 | NLTK versions before 3.10.2 contain a symlink-based sandbox bypass in FramenetCorpusReader that allows attackers to read arbitrary XML files outside the corpus root. Attackers can … | Aug 22, 2026 |
| CVE-2026-62383 | MEDIUM | 5.5 | nltk versions before 3.10.2 contain a symlink-based arbitrary file read vulnerability in IPIPANCorpusReader methods that bypass nltk.pathsec validation entirely. Attackers can place a symlink in … | Aug 22, 2026 |
| CVE-2026-75870 | UNKNOWN | — | Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The … | Aug 22, 2026 |
| CVE-2026-75866 | UNKNOWN | — | Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers … | Aug 22, 2026 |
| CVE-2026-71514 | LOW | 2.5 | NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus … | Aug 22, 2026 |
| CVE-2026-71513 | HIGH | 8.8 | NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers … | Aug 22, 2026 |
| CVE-2026-68769 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 22, 2026 |
| CVE-2026-5093 | MEDIUM | 4.3 | The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. … | Aug 22, 2026 |
| CVE-2026-4561 | MEDIUM | 6.4 | The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') … | Aug 22, 2026 |
| CVE-2026-4559 | MEDIUM | 6.4 | The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up … | Aug 22, 2026 |
| CVE-2026-2996 | HIGH | 7.5 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. … | Aug 22, 2026 |