Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
45395
Total
3650
Critical
13467
High
13391
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50187 | HIGH | 8.8 | Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a … | Aug 18, 2026 |
| CVE-2026-50139 | MEDIUM | 5.9 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, … | Aug 18, 2026 |
| CVE-2026-50138 | HIGH | 8.1 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and … | Aug 18, 2026 |
| CVE-2026-48798 | HIGH | 7.1 | SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a … | Aug 18, 2026 |
| CVE-2026-45733 | HIGH | 8.3 | Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned … | Aug 18, 2026 |
| CVE-2026-32553 | HIGH | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions. | Aug 18, 2026 |
| CVE-2026-32549 | HIGH | 7.5 | Unauthenticated Broken Access Control in ThumbPress < 6.5 versions. | Aug 18, 2026 |
| CVE-2026-32547 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions. | Aug 18, 2026 |
| CVE-2026-32481 | HIGH | 7.5 | Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions. | Aug 18, 2026 |
| CVE-2026-32474 | CRITICAL | 9.9 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | Aug 18, 2026 |
| CVE-2026-32473 | HIGH | 7.2 | Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions. | Aug 18, 2026 |
| CVE-2026-32472 | HIGH | 7.5 | Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions. | Aug 18, 2026 |
| CVE-2026-32470 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | Aug 18, 2026 |
| CVE-2026-18534 | HIGH | 7.4 | ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements … | Aug 18, 2026 |
| CVE-2026-73692 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | Aug 18, 2026 |
| CVE-2026-50575 | HIGH | 7.7 | BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a … | Aug 18, 2026 |
| CVE-2026-32468 | HIGH | 7.5 | Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions. | Aug 18, 2026 |
| CVE-2026-32467 | MEDIUM | 6.0 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | Aug 18, 2026 |
| CVE-2026-32466 | HIGH | 8.5 | Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions. | Aug 18, 2026 |
| CVE-2026-32465 | HIGH | 8.8 | Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions. | Aug 18, 2026 |
| CVE-2026-32464 | HIGH | 8.1 | Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions. | Aug 18, 2026 |
| CVE-2026-32463 | CRITICAL | 9.9 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | Aug 18, 2026 |
| CVE-2026-32444 | CRITICAL | 9.9 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | Aug 18, 2026 |
| CVE-2026-32333 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions. | Aug 18, 2026 |
| CVE-2026-28571 | HIGH | 7.5 | Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | Aug 18, 2026 |