Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13121 | HIGH | 7.8 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of … | Aug 20, 2026 |
| CVE-2026-77004 | HIGH | 7.4 | A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET§ion=ptest_sn. Executing a manipulation of the argument sn … | Aug 20, 2026 |
| CVE-2026-76999 | MEDIUM | 6.3 | A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing … | Aug 20, 2026 |
| CVE-2026-76998 | HIGH | 7.3 | A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. … | Aug 20, 2026 |
| CVE-2026-76997 | MEDIUM | 6.3 | A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This … | Aug 20, 2026 |
| CVE-2026-75140 | HIGH | 7.5 | jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by … | Aug 20, 2026 |
| CVE-2026-63044 | UNKNOWN | — | Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP … | Aug 20, 2026 |
| CVE-2026-63043 | UNKNOWN | — | Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users … | Aug 20, 2026 |
| CVE-2026-63042 | UNKNOWN | — | Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data … | Aug 20, 2026 |
| CVE-2026-63040 | UNKNOWN | — | Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. … | Aug 20, 2026 |
| CVE-2026-63039 | UNKNOWN | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value … | Aug 20, 2026 |
| CVE-2026-63038 | UNKNOWN | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code … | Aug 20, 2026 |
| CVE-2026-63037 | UNKNOWN | — | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER … | Aug 20, 2026 |
| CVE-2026-63016 | MEDIUM | 5.3 | Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 … | Aug 20, 2026 |
| CVE-2026-63015 | MEDIUM | 4.3 | Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are … | Aug 20, 2026 |
| CVE-2026-19611 | HIGH | 7.4 | A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A … | Aug 20, 2026 |
| CVE-2026-76996 | HIGH | 7.3 | A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation … | Aug 20, 2026 |
| CVE-2026-76995 | MEDIUM | 4.7 | A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of … | Aug 20, 2026 |
| CVE-2026-76993 | MEDIUM | 5.0 | A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the … | Aug 20, 2026 |
| CVE-2026-76991 | MEDIUM | 6.3 | A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Performing a manipulation of the argument … | Aug 20, 2026 |
| CVE-2026-73220 | UNKNOWN | — | CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx … | Aug 20, 2026 |
| CVE-2026-63490 | HIGH | 7.5 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment … | Aug 20, 2026 |
| CVE-2026-61898 | HIGH | 7.8 | The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is … | Aug 20, 2026 |
| CVE-2026-61897 | HIGH | 7.8 | An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user … | Aug 20, 2026 |
| CVE-2026-55558 | MEDIUM | 5.9 | aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS … | Aug 20, 2026 |