Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44839
Total
3598
Critical
13323
High
13186
Medium
CVE ID Severity Score Description Published
CVE-2026-49825 HIGH 8.2 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can … Aug 20, 2026
CVE-2026-44725 MEDIUM 6.6 EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2.1, … Aug 20, 2026
CVE-2026-16932 HIGH 8.8 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the … Aug 20, 2026
CVE-2026-16928 HIGH 7.5 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based … Aug 20, 2026
CVE-2026-16927 HIGH 7.3 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use … Aug 20, 2026
CVE-2026-16926 CRITICAL 9.1 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special … Aug 20, 2026
CVE-2026-16925 HIGH 7.1 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. Aug 20, 2026
CVE-2026-16924 HIGH 7.5 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper … Aug 20, 2026
CVE-2026-16923 HIGH 7.0 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. Aug 20, 2026
CVE-2026-16922 HIGH 7.0 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use … Aug 20, 2026
CVE-2026-76990 HIGH 7.3 A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation … Aug 20, 2026
CVE-2026-76833 HIGH 7.8 @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a custom !js YAML tag whose construct … Aug 20, 2026
CVE-2026-76635 HIGH 7.2 baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL … Aug 20, 2026
CVE-2026-76634 MEDIUM 6.5 WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by … Aug 20, 2026
CVE-2026-76633 HIGH 8.1 WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing … Aug 20, 2026
CVE-2026-76632 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 20, 2026
CVE-2026-70383 UNKNOWN Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 client. This issue affects DigiDoc4: from … Aug 20, 2026
CVE-2026-64972 UNKNOWN ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double quote into the popup parameter, break out … Aug 20, 2026
CVE-2026-64971 UNKNOWN ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, when opened, results in arbitrary JavaScript execution … Aug 20, 2026
CVE-2026-64970 UNKNOWN ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can register a new account and enter a JavaScript payload in the … Aug 20, 2026
CVE-2026-64969 UNKNOWN ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a student, can supply another user's … Aug 20, 2026
CVE-2026-64968 UNKNOWN ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary internal HTTP endpoints, cloud metadata services, … Aug 20, 2026
CVE-2026-64967 UNKNOWN A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the intended logs directory. This … Aug 20, 2026
CVE-2026-64966 UNKNOWN ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract a specially crafted ZIP … Aug 20, 2026
CVE-2026-64965 UNKNOWN ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-privileged authenticated user (e.g. a student) enrolled in a course can … Aug 20, 2026