Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
44839
Total
3598
Critical
13323
High
13186
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-66590 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Tagembed <= 7.4 versions. | Aug 20, 2026 |
| CVE-2026-66586 | MEDIUM | 6.6 | Author Local File Inclusion in WP Cafe Pro < 3.0.15 versions. | Aug 20, 2026 |
| CVE-2026-66583 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. | Aug 20, 2026 |
| CVE-2026-66582 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in TranslatePress <= 3.3.2 versions. | Aug 20, 2026 |
| CVE-2026-66581 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.14.1 versions. | Aug 20, 2026 |
| CVE-2026-28150 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Golo Framework < 1.7.5 versions. | Aug 20, 2026 |
| CVE-2025-62307 | MEDIUM | 5.4 | HCL IntelliOps Event Management (IEM) is affected by insufficient logging. Insufficient logging weakens accountability, obscures attack detection, and enables privilege probing. | Aug 20, 2026 |
| CVE-2025-53999 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Altair <= 5.2.2 versions. | Aug 20, 2026 |
| CVE-2025-15689 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. | Aug 20, 2026 |
| CVE-2025-15688 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | Aug 20, 2026 |
| CVE-2025-15637 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. | Aug 20, 2026 |
| CVE-2026-77067 | MEDIUM | 5.0 | The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file imports no validation helper. When a subscribed event fires, callWebhook … | Aug 20, 2026 |
| CVE-2026-77066 | MEDIUM | 5.0 | The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig()) with no address validation. The same file guards the subscribe path with validateUrl(), … | Aug 20, 2026 |
| CVE-2026-77026 | UNKNOWN | — | Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforce access control. An … | Aug 20, 2026 |
| CVE-2026-73199 | MEDIUM | 6.5 | A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending a malformed Lightweight … | Aug 20, 2026 |
| CVE-2026-73198 | HIGH | 7.5 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. … | Aug 20, 2026 |
| CVE-2026-73197 | HIGH | 7.5 | A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This … | Aug 20, 2026 |
| CVE-2026-73196 | MEDIUM | 4.3 | A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key value. This oversized … | Aug 20, 2026 |
| CVE-2026-13097 | CRITICAL | 9.1 | A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory server does not properly … | Aug 20, 2026 |
| CVE-2026-11861 | CRITICAL | 9.6 | A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA … | Aug 20, 2026 |
| CVE-2026-18917 | HIGH | 7.8 | A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted … | Aug 20, 2026 |
| CVE-2026-77014 | MEDIUM | 5.3 | A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subtraction result to 32-bit int, flipping … | Aug 20, 2026 |
| CVE-2026-76610 | UNKNOWN | — | Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing unauthorized tag modifications by … | Aug 20, 2026 |
| CVE-2026-14953 | MEDIUM | 4.3 | A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php. | Aug 20, 2026 |
| CVE-2026-14952 | HIGH | 7.5 | An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, … | Aug 20, 2026 |