Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45339
Total
3649
Critical
13458
High
13386
Medium
CVE ID Severity Score Description Published
CVE-2026-56873 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-56872 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-56871 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-56870 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-56869 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-56868 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-56867 UNKNOWN Rejected reason: reserved but not needed Aug 18, 2026
CVE-2026-55593 MEDIUM 6.5 Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses the centralized request validation in lib/init.php, and Ajax::handle in … Aug 18, 2026
CVE-2026-55426 HIGH 7.8 linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. … Aug 18, 2026
CVE-2026-54543 MEDIUM 5.4 Froxlor is open source server administration software. Prior to 2.3.8, the DomainZones.add API command in lib/Froxlor/Api/Commands/DomainZones.php accepts user-controlled record and type values without rejecting line … Aug 18, 2026
CVE-2026-54348 HIGH 7.2 Froxlor is open source server administration software. Prior to 2.3.8, the Admins.add and Admins.update endpoints in lib/Froxlor/Api/Commands/Admins.php accept an attacker-controlled ipaddress array and store it … Aug 18, 2026
CVE-2026-54347 HIGH 8.7 Froxlor is open source server administration software. Prior to 2.3.8, DNS TXT record content accepted by lib/Froxlor/Api/Commands/DomainZones.php can contain HTML special characters, lib/Froxlor/UI/Callbacks/Text.php returns the … Aug 18, 2026
CVE-2026-53759 UNKNOWN linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations. Prior to version 4.2.0, db_sqlite.py created SQLite databases at predictable paths in … Aug 18, 2026
CVE-2026-53458 UNKNOWN Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio backend API handlers in custom_components/blueprint_studio/backend/api.py returned raw … Aug 18, 2026
CVE-2026-53457 UNKNOWN Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, the legacy stateless terminal command execution path in custom_components/blueprint_studio/backend/terminal_manager.py … Aug 18, 2026
CVE-2026-53456 UNKNOWN Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio terminal SSH key authentication in custom_components/blueprint_studio/backend/terminal_manager.py wrote … Aug 18, 2026
CVE-2026-53455 UNKNOWN Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio generated a shell-based Git credential helper in … Aug 18, 2026
CVE-2026-53454 UNKNOWN Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio configured Git's credential.helper store when saving Git … Aug 18, 2026
CVE-2026-53453 UNKNOWN Blueprint Studio is a VS Code-like file editor for Home Assistant configuration files. Prior to 2.5.2, Blueprint Studio exposed administrator-intended backend API actions to any … Aug 18, 2026
CVE-2026-52817 UNKNOWN Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga … Aug 18, 2026
CVE-2026-52793 HIGH 8.1 Froxlor is open source server administration software. Prior to 2.3.7, the API authentication path in lib/Froxlor/Api/FroxlorRPC.php and FroxlorRPC::validateAuth accepts an API key and secret for … Aug 18, 2026
CVE-2026-41921 MEDIUM 5.4 Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows authenticated staff users to inject malicious … Aug 18, 2026
CVE-2026-18504 MEDIUM 5.4 fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a … Aug 18, 2026
CVE-2026-16732 MEDIUM 6.1 fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to … Aug 18, 2026
CVE-2026-15571 HIGH 7.3 A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to … Aug 18, 2026