Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44750
Total
3597
Critical
13289
High
13145
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-77029 | UNKNOWN | — | Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 | Aug 21, 2026 |
| CVE-2026-59318 | MEDIUM | 6.5 | In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a … | Aug 21, 2026 |
| CVE-2026-59308 | MEDIUM | 4.2 | In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared … | Aug 21, 2026 |
| CVE-2026-59279 | HIGH | 7.5 | The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default … | Aug 21, 2026 |
| CVE-2026-19848 | MEDIUM | 6.5 | The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers … | Aug 21, 2026 |
| CVE-2026-18356 | LOW | 3.7 | The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's … | Aug 21, 2026 |
| CVE-2026-17559 | MEDIUM | 5.3 | The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password … | Aug 21, 2026 |
| CVE-2026-16650 | MEDIUM | 5.3 | The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to … | Aug 21, 2026 |
| CVE-2026-15150 | MEDIUM | 5.3 | The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing … | Aug 21, 2026 |
| CVE-2026-15046 | MEDIUM | 4.2 | The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to … | Aug 21, 2026 |
| CVE-2026-13176 | LOW | 2.7 | The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access … | Aug 21, 2026 |
| CVE-2026-77769 | MEDIUM | 6.5 | The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, … | Aug 21, 2026 |
| CVE-2026-77768 | MEDIUM | 6.5 | The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries … | Aug 21, 2026 |
| CVE-2026-77767 | HIGH | 7.5 | Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject … | Aug 21, 2026 |
| CVE-2026-77763 | MEDIUM | 6.5 | The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either … | Aug 21, 2026 |
| CVE-2026-77761 | UNKNOWN | — | A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event … | Aug 21, 2026 |
| CVE-2026-77686 | MEDIUM | 5.4 | A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This … | Aug 21, 2026 |
| CVE-2026-77683 | CRITICAL | 9.9 | A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation of … | Aug 21, 2026 |
| CVE-2026-77086 | CRITICAL | 9.1 | SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal … | Aug 21, 2026 |
| CVE-2026-59296 | MEDIUM | 5.9 | Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should … | Aug 21, 2026 |
| CVE-2026-15576 | UNKNOWN | — | Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by … | Aug 21, 2026 |
| CVE-2026-14208 | UNKNOWN | — | Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) … | Aug 21, 2026 |
| CVE-2026-77755 | UNKNOWN | — | A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several … | Aug 21, 2026 |
| CVE-2026-77751 | UNKNOWN | — | A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object names are … | Aug 21, 2026 |
| CVE-2026-77681 | MEDIUM | 6.3 | A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of … | Aug 21, 2026 |