Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44793
Total
3597
Critical
13314
High
13164
Medium
CVE ID Severity Score Description Published
CVE-2026-16650 MEDIUM 5.3 The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to … Aug 21, 2026
CVE-2026-15150 MEDIUM 5.3 The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing … Aug 21, 2026
CVE-2026-15046 MEDIUM 4.2 The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to … Aug 21, 2026
CVE-2026-13176 LOW 2.7 The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access … Aug 21, 2026
CVE-2026-77769 MEDIUM 6.5 The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, … Aug 21, 2026
CVE-2026-77768 MEDIUM 6.5 The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries … Aug 21, 2026
CVE-2026-77767 HIGH 7.5 Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject … Aug 21, 2026
CVE-2026-77763 MEDIUM 6.5 The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either … Aug 21, 2026
CVE-2026-77761 UNKNOWN A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event … Aug 21, 2026
CVE-2026-77686 MEDIUM 5.4 A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This … Aug 21, 2026
CVE-2026-77683 CRITICAL 9.9 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of … Aug 21, 2026
CVE-2026-77086 CRITICAL 9.1 SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal … Aug 21, 2026
CVE-2026-59296 MEDIUM 5.9 Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should … Aug 21, 2026
CVE-2026-15576 UNKNOWN Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by … Aug 21, 2026
CVE-2026-14208 UNKNOWN Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) … Aug 21, 2026
CVE-2026-77755 UNKNOWN A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several … Aug 21, 2026
CVE-2026-77751 UNKNOWN A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object names are … Aug 21, 2026
CVE-2026-77681 MEDIUM 6.3 A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of … Aug 21, 2026
CVE-2026-59323 MEDIUM 5.3 An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation … Aug 21, 2026
CVE-2026-48590 UNKNOWN XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, … Aug 21, 2026
CVE-2026-47827 HIGH 7.5 Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities Aug 21, 2026
CVE-2026-47080 UNKNOWN XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, … Aug 21, 2026
CVE-2026-47079 UNKNOWN Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and … Aug 21, 2026
CVE-2026-77710 UNKNOWN A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between … Aug 21, 2026
CVE-2026-74866 MEDIUM 5.8 @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone … Aug 21, 2026