Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

44839
Total
3598
Critical
13323
High
13186
Medium
CVE ID Severity Score Description Published
CVE-2026-64964 UNKNOWN ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due to the use of predictable … Aug 20, 2026
CVE-2026-64963 UNKNOWN A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when the AT_FORCE_GET_FILE configuration option is enabled. This … Aug 20, 2026
CVE-2026-64962 UNKNOWN ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visited by an authenticated … Aug 20, 2026
CVE-2026-64961 UNKNOWN ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for token validation remain … Aug 20, 2026
CVE-2026-64960 UNKNOWN ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are stored … Aug 20, 2026
CVE-2026-15706 CRITICAL 9.8 Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass. This issue … Aug 20, 2026
CVE-2026-7485 UNKNOWN Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allows an authenticated user with restricted host and service visibility … Aug 20, 2026
CVE-2026-77118 UNKNOWN A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances its output pointer with … Aug 20, 2026
CVE-2026-76989 MEDIUM 5.3 A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the file source/src/enet_encap/encap.cc of the component TCP Encapsulation Receive … Aug 20, 2026
CVE-2026-76988 MEDIUM 5.3 A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_open of the file cipconnectionmanager.cc of the component ForwardOpen Handler. Executing a … Aug 20, 2026
CVE-2026-76987 HIGH 7.3 A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic … Aug 20, 2026
CVE-2026-74011 HIGH 7.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP … Aug 20, 2026
CVE-2026-28164 CRITICAL 9.6 Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7. Aug 20, 2026
CVE-2026-28163 MEDIUM 5.3 Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through … Aug 20, 2026
CVE-2026-21784 MEDIUM 4.8 HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes the application's environment and resources susceptible to unauthorized … Aug 20, 2026
CVE-2026-18482 UNKNOWN Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled absolutePath … Aug 20, 2026
CVE-2025-62306 MEDIUM 5.0 HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflow. if an attacker were … Aug 20, 2026
CVE-2025-62300 MEDIUM 5.9 HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing unpredictable … Aug 20, 2026
CVE-2025-62299 MEDIUM 6.6 HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the elevated privilege … Aug 20, 2026
CVE-2026-77085 UNKNOWN n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied API … Aug 20, 2026
CVE-2026-77084 UNKNOWN n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git … Aug 20, 2026
CVE-2026-77083 UNKNOWN n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's … Aug 20, 2026
CVE-2026-77082 UNKNOWN n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, … Aug 20, 2026
CVE-2026-77081 UNKNOWN n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication parameter is set … Aug 20, 2026
CVE-2026-77080 UNKNOWN n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form … Aug 20, 2026