Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-20030 | CRITICAL | 10.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This … | Aug 19, 2026 |
| CVE-2024-13942 | HIGH | 7.6 | Secure BootROM of RK3588s SoC is vulnerable to a time-of-check to time-of-use attack in case of booting from external media (SPI NOR or NAND, EMMC … | Aug 19, 2026 |
| CVE-2026-64852 | UNKNOWN | — | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.8, the Grav API … | Aug 19, 2026 |
| CVE-2026-64851 | UNKNOWN | — | Grav Shortcode Core Plugin allows for the development shortcode plugins that utilize the common format utilized by WordPress and BBCode. Prior to 6.2.2, Grav Shortcode … | Aug 19, 2026 |
| CVE-2026-64850 | UNKNOWN | — | Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous … | Aug 19, 2026 |
| CVE-2026-63408 | HIGH | 7.5 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API … | Aug 19, 2026 |
| CVE-2026-63407 | HIGH | 8.2 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0-rc.16, the Grav API … | Aug 19, 2026 |
| CVE-2026-62673 | UNKNOWN | — | Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive … | Aug 19, 2026 |
| CVE-2026-62672 | UNKNOWN | — | Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly … | Aug 19, 2026 |
| CVE-2026-62671 | MEDIUM | 5.4 | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level … | Aug 19, 2026 |
| CVE-2026-62670 | MEDIUM | 6.3 | Grav Flex Objects Plugin allows you to build custom collections of objects. Prior to 1.4.3, the Grav Flex Objects Admin Next API requireFlexPermission() method in … | Aug 19, 2026 |
| CVE-2026-62669 | HIGH | 7.4 | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that … | Aug 19, 2026 |
| CVE-2026-62668 | UNKNOWN | — | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API … | Aug 19, 2026 |
| CVE-2026-62667 | HIGH | 8.1 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API … | Aug 19, 2026 |
| CVE-2026-62666 | HIGH | 8.8 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, Grav API plugin … | Aug 19, 2026 |
| CVE-2026-61842 | MEDIUM | 6.5 | Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, … | Aug 19, 2026 |
| CVE-2026-61690 | MEDIUM | 6.5 | Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, file-count, or nesting-depth … | Aug 19, 2026 |
| CVE-2026-61607 | MEDIUM | 4.6 | Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.2, the Grav API … | Aug 19, 2026 |
| CVE-2026-53654 | UNKNOWN | — | Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and allows an … | Aug 19, 2026 |
| CVE-2026-46343 | UNKNOWN | — | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.end_receiving_file() in framework/wazuh/core/cluster/common.py allows … | Aug 19, 2026 |
| CVE-2026-44254 | MEDIUM | 5.3 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMessage() in src/remoted/secure.c passes … | Aug 19, 2026 |
| CVE-2026-44253 | MEDIUM | 4.9 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 3.9.0 until 4.14.5 and 5.0.0-beta2, the Wazuh cluster protocol … | Aug 19, 2026 |
| CVE-2026-44252 | UNKNOWN | — | Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-privilege read-only … | Aug 19, 2026 |
| CVE-2026-19672 | UNKNOWN | — | The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and returns to it, such … | Aug 19, 2026 |
| CVE-2026-18430 | UNKNOWN | — | HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete another user's comment, choose to notify the … | Aug 19, 2026 |