Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-62684 | LOW | 2.7 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage … | Aug 18, 2026 |
| CVE-2026-62357 | UNKNOWN | — | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whose width times depth times sizeof(int64_t) … | Aug 18, 2026 |
| CVE-2026-55839 | HIGH | 8.7 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link.ts allows a user with permission to create or update … | Aug 18, 2026 |
| CVE-2026-49227 | HIGH | 7.6 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment … | Aug 18, 2026 |
| CVE-2026-49226 | HIGH | 8.3 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post … | Aug 18, 2026 |
| CVE-2026-49221 | HIGH | 8.8 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital … | Aug 18, 2026 |
| CVE-2026-47245 | MEDIUM | 4.3 | MyBB is free and open source forum software. Prior to 1.8.40, the User CP Buddy/Ignore List component does not validate reciprocal buddy-list updates correctly. The … | Aug 18, 2026 |
| CVE-2026-46482 | MEDIUM | 5.3 | ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challenge via a specially crafted value. … | Aug 18, 2026 |
| CVE-2026-45734 | MEDIUM | 5.3 | MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remote attackers to bypass … | Aug 18, 2026 |
| CVE-2026-45129 | MEDIUM | 4.6 | MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers … | Aug 18, 2026 |
| CVE-2026-45128 | LOW | 3.5 | MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers … | Aug 18, 2026 |
| CVE-2026-45127 | LOW | 3.5 | MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers … | Aug 18, 2026 |
| CVE-2026-45126 | LOW | 3.5 | MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing … | Aug 18, 2026 |
| CVE-2026-45125 | MEDIUM | 5.3 | MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header … | Aug 18, 2026 |
| CVE-2026-45124 | MEDIUM | 4.3 | MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management … | Aug 18, 2026 |
| CVE-2026-45123 | MEDIUM | 4.3 | MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side … | Aug 18, 2026 |
| CVE-2026-45122 | MEDIUM | 4.3 | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving … | Aug 18, 2026 |
| CVE-2026-45121 | MEDIUM | 4.3 | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users … | Aug 18, 2026 |
| CVE-2026-45120 | MEDIUM | 5.4 | MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing … | Aug 18, 2026 |
| CVE-2026-45119 | MEDIUM | 4.6 | MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site … | Aug 18, 2026 |
| CVE-2026-45118 | CRITICAL | 9.3 | MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in … | Aug 18, 2026 |
| CVE-2026-45117 | CRITICAL | 9.8 | MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to … | Aug 18, 2026 |
| CVE-2026-45116 | HIGH | 8.7 | MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting … | Aug 18, 2026 |
| CVE-2026-45115 | HIGH | 8.7 | MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code … | Aug 18, 2026 |
| CVE-2026-19501 | UNKNOWN | — | CSV export functionality in Brainstorm Force SureForms version, <= 2.1.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, … | Aug 18, 2026 |