Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

45395
Total
3650
Critical
13467
High
13391
Medium
CVE ID Severity Score Description Published
CVE-2026-50187 HIGH 8.8 Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a … Aug 18, 2026
CVE-2026-50139 MEDIUM 5.9 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, … Aug 18, 2026
CVE-2026-50138 HIGH 8.1 goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and … Aug 18, 2026
CVE-2026-48798 HIGH 7.1 SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a … Aug 18, 2026
CVE-2026-45733 HIGH 8.3 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned … Aug 18, 2026
CVE-2026-32553 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. Aug 18, 2026
CVE-2026-32549 HIGH 7.5 Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. Aug 18, 2026
CVE-2026-32547 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. Aug 18, 2026
CVE-2026-32481 HIGH 7.5 Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. Aug 18, 2026
CVE-2026-32474 CRITICAL 9.9 Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. Aug 18, 2026
CVE-2026-32473 HIGH 7.2 Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. Aug 18, 2026
CVE-2026-32472 HIGH 7.5 Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. Aug 18, 2026
CVE-2026-32470 CRITICAL 9.8 Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. Aug 18, 2026
CVE-2026-18534 HIGH 7.4 ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements … Aug 18, 2026
CVE-2026-73692 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Aug 18, 2026
CVE-2026-50575 HIGH 7.7 BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a … Aug 18, 2026
CVE-2026-32468 HIGH 7.5 Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. Aug 18, 2026
CVE-2026-32467 MEDIUM 6.0 Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. Aug 18, 2026
CVE-2026-32466 HIGH 8.5 Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. Aug 18, 2026
CVE-2026-32465 HIGH 8.8 Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. Aug 18, 2026
CVE-2026-32464 HIGH 8.1 Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. Aug 18, 2026
CVE-2026-32463 CRITICAL 9.9 Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. Aug 18, 2026
CVE-2026-32444 CRITICAL 9.9 Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. Aug 18, 2026
CVE-2026-32333 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. Aug 18, 2026
CVE-2026-28571 HIGH 7.5 Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. Aug 18, 2026