Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49825 | HIGH | 8.2 | lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can … | Aug 20, 2026 |
| CVE-2026-44725 | MEDIUM | 6.6 | EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, … | Aug 20, 2026 |
| CVE-2026-16932 | HIGH | 8.8 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the … | Aug 20, 2026 |
| CVE-2026-16928 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based … | Aug 20, 2026 |
| CVE-2026-16927 | HIGH | 7.3 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use … | Aug 20, 2026 |
| CVE-2026-16926 | CRITICAL | 9.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special … | Aug 20, 2026 |
| CVE-2026-16925 | HIGH | 7.1 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. | Aug 20, 2026 |
| CVE-2026-16924 | HIGH | 7.5 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper … | Aug 20, 2026 |
| CVE-2026-16923 | HIGH | 7.0 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. | Aug 20, 2026 |
| CVE-2026-16922 | HIGH | 7.0 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use … | Aug 20, 2026 |
| CVE-2026-76990 | HIGH | 7.3 | A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation … | Aug 20, 2026 |
| CVE-2026-76833 | HIGH | 7.8 | @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct … | Aug 20, 2026 |
| CVE-2026-76635 | HIGH | 7.2 | baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL … | Aug 20, 2026 |
| CVE-2026-76634 | MEDIUM | 6.5 | WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by … | Aug 20, 2026 |
| CVE-2026-76633 | HIGH | 8.1 | WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing … | Aug 20, 2026 |
| CVE-2026-76632 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 20, 2026 |
| CVE-2026-70383 | UNKNOWN | — | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from … | Aug 20, 2026 |
| CVE-2026-64972 | UNKNOWN | — | ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out … | Aug 20, 2026 |
| CVE-2026-64971 | UNKNOWN | — | ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution … | Aug 20, 2026 |
| CVE-2026-64970 | UNKNOWN | — | ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can register a new account and enter a JavaScript payload in the … | Aug 20, 2026 |
| CVE-2026-64969 | UNKNOWN | — | ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's … | Aug 20, 2026 |
| CVE-2026-64968 | UNKNOWN | — | ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, … | Aug 20, 2026 |
| CVE-2026-64967 | UNKNOWN | — | A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This … | Aug 20, 2026 |
| CVE-2026-64966 | UNKNOWN | — | ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP … | Aug 20, 2026 |
| CVE-2026-64965 | UNKNOWN | — | ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-privileged authenticated user (e.g. a student) enrolled in a course can … | Aug 20, 2026 |