Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45002
Total
3609
Critical
13358
High
13243
Medium
CVE ID Severity Score Description Published
CVE-2026-73347 CRITICAL 9.8 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions. Aug 19, 2026
CVE-2026-73185 CRITICAL 9.3 Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. Aug 19, 2026
CVE-2026-73184 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions. Aug 19, 2026
CVE-2026-73183 CRITICAL 9.3 Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. Aug 19, 2026
CVE-2026-73182 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions. Aug 19, 2026
CVE-2026-67364 UNKNOWN Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) The … Aug 19, 2026
CVE-2026-67363 UNKNOWN Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept the charge total from … Aug 19, 2026
CVE-2026-66668 HIGH 8.5 Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions. Aug 19, 2026
CVE-2026-66613 CRITICAL 9.8 Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. Aug 19, 2026
CVE-2026-66596 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions. Aug 19, 2026
CVE-2026-61986 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions. Aug 19, 2026
CVE-2026-32552 HIGH 8.5 Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions. Aug 19, 2026
CVE-2026-19490 UNKNOWN Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 … Aug 19, 2026
CVE-2026-19489 UNKNOWN Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 … Aug 19, 2026
CVE-2026-18372 UNKNOWN CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other … Aug 19, 2026
CVE-2026-18371 UNKNOWN HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. Aug 19, 2026
CVE-2026-16440 UNKNOWN In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault. Aug 19, 2026
CVE-2026-76166 MEDIUM 4.3 A flaw was found in mod_cluster's AdvertiseListenerImpl (org.jboss.modcluster core module). A single crafted UDP multicast datagram with a valid HTTP status line and a "Server:" … Aug 19, 2026
CVE-2026-76164 UNKNOWN AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated user with access to the crawler interface can … Aug 19, 2026
CVE-2026-75900 MEDIUM 6.1 An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(bh), where bh is a pointer, instead … Aug 19, 2026
CVE-2026-75589 UNKNOWN Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256 and PLAINTEXT signatures with a non-constant-time comparison in verify. Each of the three compares the signature … Aug 19, 2026
CVE-2026-72889 UNKNOWN Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method … Aug 19, 2026
CVE-2026-58088 HIGH 7.4 The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over the … Aug 19, 2026
CVE-2026-58087 HIGH 7.8 The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buffer … Aug 19, 2026
CVE-2026-58086 UNKNOWN As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user. Tracing configured by a jailed root … Aug 19, 2026