Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41940
Total
3420
Critical
12400
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-81292 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions. Sep 03, 2026
CVE-2026-81282 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. Sep 03, 2026
CVE-2026-81281 MEDIUM 6.5 Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. Sep 03, 2026
CVE-2026-75602 MEDIUM 6.5 OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL … Sep 03, 2026
CVE-2026-85239 UNKNOWN A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template … Sep 03, 2026
CVE-2026-85238 UNKNOWN MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the … Sep 03, 2026
CVE-2026-85237 UNKNOWN A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint … Sep 03, 2026
CVE-2026-85236 UNKNOWN A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET … Sep 03, 2026
CVE-2026-85138 HIGH 7.3 A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation … Sep 03, 2026
CVE-2026-85137 HIGH 7.3 A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. … Sep 03, 2026
CVE-2026-84967 MEDIUM 4.3 A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into … Sep 03, 2026
CVE-2026-84966 MEDIUM 5.1 An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. … Sep 03, 2026
CVE-2026-84965 MEDIUM 5.1 An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following … Sep 03, 2026
CVE-2026-84964 MEDIUM 5.9 A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the … Sep 03, 2026
CVE-2026-84963 MEDIUM 5.3 An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be … Sep 03, 2026
CVE-2026-84962 MEDIUM 4.2 An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized … Sep 03, 2026
CVE-2026-83961 HIGH 7.1 ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and … Sep 03, 2026
CVE-2026-82525 MEDIUM 5.5 Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by … Sep 03, 2026
CVE-2026-75036 UNKNOWN A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. … Sep 03, 2026
CVE-2026-75035 HIGH 7.7 A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its … Sep 03, 2026
CVE-2026-75034 HIGH 7.4 A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process … Sep 03, 2026
CVE-2026-71963 HIGH 8.8 Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying … Sep 03, 2026
CVE-2026-57445 UNKNOWN Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b … Sep 03, 2026
CVE-2026-55658 HIGH 7.7 Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 … Sep 03, 2026
CVE-2026-53924 UNKNOWN Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to … Sep 03, 2026