Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45002
Total
3609
Critical
13358
High
13243
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-54796 | HIGH | 7.2 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high … | Aug 19, 2026 |
| CVE-2026-54795 | HIGH | 8.8 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low … | Aug 19, 2026 |
| CVE-2026-54794 | HIGH | 7.2 | Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, … | Aug 19, 2026 |
| CVE-2026-51367 | UNKNOWN | — | An issue in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to obtain sensitive information via the api_vedo/chat endpoint and the utente_chat parameter | Aug 19, 2026 |
| CVE-2026-51366 | UNKNOWN | — | SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter | Aug 19, 2026 |
| CVE-2026-50720 | UNKNOWN | — | The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word … | Aug 19, 2026 |
| CVE-2026-50719 | UNKNOWN | — | The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before … | Aug 19, 2026 |
| CVE-2026-43961 | HIGH | 7.8 | A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during … | Aug 19, 2026 |
| CVE-2026-16019 | CRITICAL | 9.8 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects … | Aug 19, 2026 |
| CVE-2024-58376 | HIGH | 8.8 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary … | Aug 19, 2026 |
| CVE-2020-37267 | HIGH | 7.5 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION … | Aug 19, 2026 |
| CVE-2019-25766 | HIGH | 7.5 | Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scenarios. The issue is … | Aug 19, 2026 |
| CVE-2026-76235 | HIGH | 7.5 | A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, … | Aug 19, 2026 |
| CVE-2026-73394 | HIGH | 7.5 | Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. | Aug 19, 2026 |
| CVE-2026-73391 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | Aug 19, 2026 |
| CVE-2026-73390 | CRITICAL | 9.8 | Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. | Aug 19, 2026 |
| CVE-2026-73389 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. | Aug 19, 2026 |
| CVE-2026-73388 | CRITICAL | 9.3 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | Aug 19, 2026 |
| CVE-2026-73387 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Resido <= 1.5 versions. | Aug 19, 2026 |
| CVE-2026-73386 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. | Aug 19, 2026 |
| CVE-2026-73385 | HIGH | 7.5 | Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions. | Aug 19, 2026 |
| CVE-2026-73384 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions. | Aug 19, 2026 |
| CVE-2026-73364 | CRITICAL | 9.8 | Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions. | Aug 19, 2026 |
| CVE-2026-73363 | MEDIUM | 6.5 | Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions. | Aug 19, 2026 |
| CVE-2026-73354 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions. | Aug 19, 2026 |