Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-64964 | UNKNOWN | — | ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable … | Aug 20, 2026 |
| CVE-2026-64963 | UNKNOWN | — | A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This … | Aug 20, 2026 |
| CVE-2026-64962 | UNKNOWN | — | ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated … | Aug 20, 2026 |
| CVE-2026-64961 | UNKNOWN | — | ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain … | Aug 20, 2026 |
| CVE-2026-64960 | UNKNOWN | — | ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored … | Aug 20, 2026 |
| CVE-2026-15706 | CRITICAL | 9.8 | Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue … | Aug 20, 2026 |
| CVE-2026-7485 | UNKNOWN | — | Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility … | Aug 20, 2026 |
| CVE-2026-77118 | UNKNOWN | — | A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with … | Aug 20, 2026 |
| CVE-2026-76989 | MEDIUM | 5.3 | A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive … | Aug 20, 2026 |
| CVE-2026-76988 | MEDIUM | 5.3 | A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_open of the file cipconnectionmanager.cc of the component ForwardOpen Handler. Executing a … | Aug 20, 2026 |
| CVE-2026-76987 | HIGH | 7.3 | A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic … | Aug 20, 2026 |
| CVE-2026-74011 | HIGH | 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP … | Aug 20, 2026 |
| CVE-2026-28164 | CRITICAL | 9.6 | Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. | Aug 20, 2026 |
| CVE-2026-28163 | MEDIUM | 5.3 | Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through … | Aug 20, 2026 |
| CVE-2026-21784 | MEDIUM | 4.8 | HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized … | Aug 20, 2026 |
| CVE-2026-18482 | UNKNOWN | — | Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath … | Aug 20, 2026 |
| CVE-2025-62306 | MEDIUM | 5.0 | HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were … | Aug 20, 2026 |
| CVE-2025-62300 | MEDIUM | 5.9 | HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable … | Aug 20, 2026 |
| CVE-2025-62299 | MEDIUM | 6.6 | HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege … | Aug 20, 2026 |
| CVE-2026-77085 | UNKNOWN | — | n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API … | Aug 20, 2026 |
| CVE-2026-77084 | UNKNOWN | — | n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git … | Aug 20, 2026 |
| CVE-2026-77083 | UNKNOWN | — | n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's … | Aug 20, 2026 |
| CVE-2026-77082 | UNKNOWN | — | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, … | Aug 20, 2026 |
| CVE-2026-77081 | UNKNOWN | — | n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set … | Aug 20, 2026 |
| CVE-2026-77080 | UNKNOWN | — | n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form … | Aug 20, 2026 |