Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45002
Total
3609
Critical
13358
High
13243
Medium
CVE ID Severity Score Description Published
CVE-2026-53451 CRITICAL 9.8 Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command … Aug 19, 2026
CVE-2026-52889 CRITICAL 9.8 Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer … Aug 19, 2026
CVE-2026-52834 HIGH 7.3 jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform … Aug 19, 2026
CVE-2026-52792 UNKNOWN Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first … Aug 19, 2026
CVE-2026-50149 MEDIUM 6.5 Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: … Aug 19, 2026
CVE-2026-49817 HIGH 7.8 Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … Aug 19, 2026
CVE-2026-49816 HIGH 7.8 Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit … Aug 19, 2026
CVE-2026-49289 HIGH 7.5 The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML … Aug 19, 2026
CVE-2026-49283 HIGH 8.7 The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat … Aug 19, 2026
CVE-2026-49255 HIGH 8.8 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), … Aug 19, 2026
CVE-2026-49253 HIGH 7.1 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/zmodem.js, prepareReceiveFile() … Aug 19, 2026
CVE-2026-48711 HIGH 7.0 SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oProxyCommand=CMD]:/path … Aug 19, 2026
CVE-2026-47187 CRITICAL 9.3 SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or … Aug 19, 2026
CVE-2026-45742 HIGH 7.5 Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one errgroup.Go goroutine for each multipart … Aug 19, 2026
CVE-2026-45741 HIGH 7.5 Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not reject the 2002::/16 6to4 prefix, … Aug 19, 2026
CVE-2026-45274 UNKNOWN MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce … Aug 19, 2026
CVE-2026-45273 UNKNOWN MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings in webserver/handlers/admin.py applies the … Aug 19, 2026
CVE-2026-45272 UNKNOWN MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts … Aug 19, 2026
CVE-2026-44829 HIGH 8.8 Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base on Linux, which does not treat … Aug 19, 2026
CVE-2026-40509 MEDIUM 4.3 OpenEMR before 8.3.0 contains a cross-site request forgery vulnerability in the DICOM viewer. The web_path GET parameter in the DICOM viewer page is embedded unsanitized … Aug 19, 2026
CVE-2026-40508 MEDIUM 5.4 OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated attackers with Forms Administration permissions to … Aug 19, 2026
CVE-2026-40507 MEDIUM 6.1 OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET parameter is reflected into the page … Aug 19, 2026
CVE-2026-32802 MEDIUM 5.3 Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this … Aug 19, 2026
CVE-2026-23501 HIGH 7.2 Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A … Aug 19, 2026
CVE-2026-18756 UNKNOWN HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can place attacker-controlled button configuration in the options … Aug 19, 2026