Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44793
Total
3597
Critical
13314
High
13164
Medium
CVE ID Severity Score Description Published
CVE-2026-48752 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read … Aug 21, 2026
CVE-2026-48751 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on … Aug 21, 2026
CVE-2026-48750 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the … Aug 21, 2026
CVE-2026-48749 CRITICAL 9.9 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary … Aug 21, 2026
CVE-2026-47753 UNKNOWN Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with … Aug 21, 2026
CVE-2026-77806 CRITICAL 9.8 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection … Aug 21, 2026
CVE-2026-75946 UNKNOWN A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentially allow a local attacker … Aug 21, 2026
CVE-2026-15580 UNKNOWN vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal browser extension: before 3.49.6. Aug 21, 2026
CVE-2026-77780 UNKNOWN Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting … Aug 21, 2026
CVE-2026-77028 UNKNOWN Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 Aug 21, 2026
CVE-2026-76613 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-level user to inject own content … Aug 21, 2026
CVE-2026-76612 UNKNOWN Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user supplied field … Aug 21, 2026
CVE-2026-76611 UNKNOWN Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. Aug 21, 2026
CVE-2026-75115 UNKNOWN Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is vulnerable to glob-based pattern … Aug 21, 2026
CVE-2026-59654 UNKNOWN Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects different modules and plugins of the CloudStack management … Aug 21, 2026
CVE-2026-77776 CRITICAL 9.1 Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat … Aug 21, 2026
CVE-2026-77775 HIGH 8.6 Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the header value, requires only that … Aug 21, 2026
CVE-2026-77759 UNKNOWN Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions … Aug 21, 2026
CVE-2026-77029 UNKNOWN Joomla Extension - yootheme.com - Missing CSRF tokens on front-end state changes in Zoo < 4.1.66 Aug 21, 2026
CVE-2026-59318 MEDIUM 6.5 In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a … Aug 21, 2026
CVE-2026-59308 MEDIUM 4.2 In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared … Aug 21, 2026
CVE-2026-59279 HIGH 7.5 The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default … Aug 21, 2026
CVE-2026-19848 MEDIUM 6.5 The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allowing unauthenticated attackers … Aug 21, 2026
CVE-2026-18356 LOW 3.7 The Limit Login Attempts Reloaded WordPress plugin before 3.3.5 does not compare logins against its username denylist case-insensitively and does not account for the account's … Aug 21, 2026
CVE-2026-17559 MEDIUM 5.3 The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass global password … Aug 21, 2026