Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44839
Total
3598
Critical
13323
High
13186
Medium
CVE ID Severity Score Description Published
CVE-2026-13121 HIGH 7.8 Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of … Aug 20, 2026
CVE-2026-77004 HIGH 7.4 A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn … Aug 20, 2026
CVE-2026-76999 MEDIUM 6.3 A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing … Aug 20, 2026
CVE-2026-76998 HIGH 7.3 A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. … Aug 20, 2026
CVE-2026-76997 MEDIUM 6.3 A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This … Aug 20, 2026
CVE-2026-75140 HIGH 7.5 jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by … Aug 20, 2026
CVE-2026-63044 UNKNOWN Server-Side Request Forgery (SSRF) vulnerability in Apache InLong. Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP … Aug 20, 2026
CVE-2026-63043 UNKNOWN Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users … Aug 20, 2026
CVE-2026-63042 UNKNOWN Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data … Aug 20, 2026
CVE-2026-63040 UNKNOWN Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. … Aug 20, 2026
CVE-2026-63039 UNKNOWN Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value … Aug 20, 2026
CVE-2026-63038 UNKNOWN Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code … Aug 20, 2026
CVE-2026-63037 UNKNOWN Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER … Aug 20, 2026
CVE-2026-63016 MEDIUM 5.3 Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 … Aug 20, 2026
CVE-2026-63015 MEDIUM 4.3 Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are … Aug 20, 2026
CVE-2026-19611 HIGH 7.4 A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A … Aug 20, 2026
CVE-2026-76996 HIGH 7.3 A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation … Aug 20, 2026
CVE-2026-76995 MEDIUM 4.7 A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of … Aug 20, 2026
CVE-2026-76993 MEDIUM 5.0 A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the … Aug 20, 2026
CVE-2026-76991 MEDIUM 6.3 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Performing a manipulation of the argument … Aug 20, 2026
CVE-2026-73220 UNKNOWN CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx … Aug 20, 2026
CVE-2026-63490 HIGH 7.5 Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment … Aug 20, 2026
CVE-2026-61898 HIGH 7.8 The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is … Aug 20, 2026
CVE-2026-61897 HIGH 7.8 An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user … Aug 20, 2026
CVE-2026-55558 MEDIUM 5.9 aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the server's 220 response and starts the TLS … Aug 20, 2026